SupplementaryMaterial

Neural Information Processing Systems 

Using targeted attack strategy allows us to include the randomness of the target label sampling. We choose Jester dataset as it generally takes few queries to attack Jester dataset, thussavingtesting time. GEO-TRAP can employ different kinds of geometric transformations in theTRANS-WARP function. Thisisdemonstrated bythefactthatGEO-TRAP'sgradients generally have larger cosine similarity with the ground truth gradients. Wedenote the probability score associated with this label aspy(x).

Similar Docs  Excel Report  more

TitleSimilaritySource
None found