A Little Robustness Goes a Long Way: Leveraging Robust Features for Targeted Transfer Attacks
–Neural Information Processing Systems
Here, we show that training the source classifier to be "slightly robust"--that is, robust to small-magnitude
Neural Information Processing Systems
Aug-14-2025, 11:45:16 GMT
- Country:
- North America > United States
- Massachusetts (0.04)
- New Mexico
- Los Alamos County > Los Alamos (0.05)
- Santa Fe County > Santa Fe (0.04)
- North America > United States
- Genre:
- Research Report (0.46)
- Industry:
- Government (0.69)
- Information Technology (0.46)
- Technology: