Frequency domain model augmentation for adversarial attack

Y Long, Q Zhang, B Zeng, L Gao, X Liu, J Zhang… - European conference on …, 2022 - Springer
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …

Frequency Domain Model Augmentation for Adversarial Attack

Y Long, Q Zhang, B Zeng, L Gao, X Liu, J Zhang… - arXiv preprint arXiv …, 2022 - arxiv.org
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …

Frequency Domain Model Augmentation for Adversarial Attack

Y Long, Q Zhang, B Zeng, L Gao, X Liu… - … on Computer Vision, 2022 - dl.acm.org
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …

[PDF][PDF] Frequency Domain Model Augmentation for Adversarial Attack

Y Long, Q Zhang, B Zeng, L Gao, X Liu, J Zhang… - ecva.net
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …

Frequency Domain Model Augmentation for Adversarial Attack

Y Long, Q Zhang, B Zeng, L Gao, X Liu… - arXiv e …, 2022 - ui.adsabs.harvard.edu
For black-box attacks, the gap between the substitute model and the victim model is usually
large, which manifests as a weak attack performance. Motivated by the observation that the …