Hi!
I am glad to read such a very interesting paper.
I recently experimented with your code on nips-1k and was confused about the results. (ResNet50)
The attack success rate of the output is 91.6%. But when I tested the saved adversarial samples, the success rate of the attack was only 87.2%. What is the reason for this? Is it reasonable?
Thanks!
Hi!
I am glad to read such a very interesting paper.
I recently experimented with your code on nips-1k and was confused about the results. (ResNet50)
The attack success rate of the output is 91.6%. But when I tested the saved adversarial samples, the success rate of the attack was only 87.2%. What is the reason for this? Is it reasonable?
Thanks!