Finding Optimal Tangent Points for Reducing Distortions of Hard-label Attacks Li Chen
–Neural Information Processing Systems
One major problem in black-box adversarial attacks is the high query complexity in the hard-label attack setting, where only the top-1 predicted label is available. In this paper, we propose a novel geometric-based approach called Tangent Attack (TA), which identifies an optimal tangent point of a virtual hemisphere located on the decision boundary to reduce the distortion of the attack.
Neural Information Processing Systems
Feb-9-2025, 18:35:39 GMT