-
Notifications
You must be signed in to change notification settings - Fork 42
Open
Description
I am trying to attack the google cloud vision api using your code and i was checking on the video you posted about the attacking process. I have some questions about it:
There seems to be some images where the label dog are not among the predicted labels, for examples https://youtu.be/1h9bU7WBTUg?t=43. But I think the partial information attack depends on the target class staying in the predicted labels. So there seems to be contradiction here? Is the video showing the generated images at every iteration?
Also, what is the k used in the attacking the google cloud vision api?
Metadata
Metadata
Assignees
Labels
No labels