A Additional experiments
–Neural Information Processing Systems
A.1 Additional experiments on other pre-trained models In this section, we report the results on CLIP and MOCO in Table 1 and Table 2, respectively. Note that the first seven columns of validation datasets are fine-grained, while the next three are coarse-grained ones. We mark the best results for each dataset in bold, and the best baseline in blue . These tables show that our proposed methods outperform all the baselines by a large margin. For example, as can be seen from Table 1, if the target model is Resnet50 pre-trained by MOCO, the best competitor UAP achieves an average attack success rate of 54.34%, while the L4A Table 1: The attack success rate(%) of various methods we study against Resnet50 pretrained by MOCO.
Neural Information Processing Systems
Oct-1-2025, 23:01:35 GMT