Supplementary Materials of Random Noise Defense against Query-Based Black-Box Attacks Zeyu Qin 1 Y anbo Fan

Neural Information Processing Systems 

In this supplementary document, we provide additional materials to supplement our main submission. In Section A, we talk about the societal impacts of our work In Section B, we provide detailed experimental settings as well as further evaluation results on CIFAR-10 and ImageNet. In Section D, we give the proofs w.r .t . In Section E, we give the proofs w.r .t . The proofs of Theorem 3 are given in Section F. In Section C, we provide the analysis and evaluation of decision-based attacks.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found