-
Notifications
You must be signed in to change notification settings - Fork 42
Open
Description
I tried the blackbox attack on MNIST with a simple LeNet model. I didn't change the parameters, except the number of classes. I wasn't able to make the attack successful even under the query_limited case after 1 million queries.
The attack is only successful when EPSILON is larger than 0.1.
Is there any recommendation on how to update the parameters to make the attack successful in MNIST?
Thanks!
Metadata
Metadata
Assignees
Labels
No labels