I tried FGSM attack on MNIST clean dataset, and I got 49% accuracy,
which is too large compared to 6.4% [Madry, https://arxiv.org/pdf/1706.06083.pdf]
Am i missing something?
I'd like to ask if anyone else has done a FGSM attack against mnist, what performance you got?.