φ (x; null w
–Neural Information Processing Systems
Built upon Eq. 7, we have The architecture of surrogate models is modified to avoid overfitting. To make the conclusion clearer, we also report the performance of a general surrogate model, which is trained on the training set of target models. Specifically, the common sense in black-box attacks is that mounting attacks requires a surrogate model, which generalizes well on the test set. Similarly, "First" means only applying ETF to the first layer. We conduct experiments using GEFORCE RTX 2080 Ti, CPU AMD Ryzen 7 3700X @3.6 GHz.
Neural Information Processing Systems
Nov-20-2025, 09:33:59 GMT