BackpropagatingLinearlyImprovesTransferability ofAdversarialExamples(SupplementaryMaterial)
–Neural Information Processing Systems
Table8: Success ratesoftransfer-based attacks onImageNetusingDI2-FGSM. Thesource model is aResNet-50 and the symbol * indicates that the victim model is the same as the source model. The mean and standard deviation results of five runs are reported. Average is obtained from models differentfromthesource.Dataset Method ResNet* (2016) Inceptionv3 (2016) DenseNet (2017) MobileNetv2 (2018) PNASNet (2018) SENet (2018) Average
Neural Information Processing Systems
Feb-7-2026, 07:08:07 GMT
- Country: