TL;DR通过使用不同域中的数据增强,我们提出了一种名为Style Transfer Method(STM)的新的攻击方法,利用提出的任意风格转换网络将图像转换为不同的域,从而显著提高了对抗性可转移性。
Abstract
Deep neural networks are vulnerable to adversarial examples crafted by applying human-imperceptible perturbations on clean inputs. Although many attack methods can achieve high success rates in the white-box setting, they also exhibit weak →