Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks Sizhe Chen

Neural Information Processing Systems 

Following this idea, we propose a novel defense, namely Adversarial Attack on Attackers (AAA), to confound SQAs towards incorrect attack directions by slightly modifying the output logits.