Y Long, Q Zhang, B Zeng, L Gao, X Liu, J Zhang… - arXiv preprint arXiv …, 2022 - arxiv.org
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …