Reviews: Functional Adversarial Attacks
–Neural Information Processing Systems
For the second question, I would like to see more instances of functional attacks, which could be also applied to image classification. Given such results would make this paper stronger. I will keep my original rating. A typical type of functional adversarial attacks is realized by changing the color of images as ReColorAdv. The constrains on this attack and the optimization process is clearly illustrated.
Neural Information Processing Systems
Jan-24-2025, 14:54:48 GMT