Clarification of the MESA method (Review Methods Average ASR Methods Average ASR 2.04% 1.42% 1.93%
–Neural Information Processing Systems
From the feature space's perspective, we can assume that We add several experiments using random-color triggers as shown in Figure 1. CIFAR-100 (Figure 1(b), random target class) to show the marginal effect of dataset and target class choices. Regarding to Reviewer #4's concern about the size of the support set, the choice of black-white and colorful triggers The only prior knowledge is the 3 3 trigger size. Comparing to related works about model ensembling (Review #5). The model ensembling in this work has a completely different motivation.
Neural Information Processing Systems
Feb-11-2025, 22:20:12 GMT
- Technology: