Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack Transferability
–Neural Information Processing Systems
We focus on the blackbox transfer-based adversarial threat model for DNN image classifiers. In the standard case, blackbox means the attacker does not have access to the gradients of the target model and makes no assumptions about its architecture.
Neural Information Processing Systems
Aug-17-2025, 04:46:46 GMT