1 code implementation • 26 Sep 2023 • Liu jun, Zhou Jiantao, Zeng Jiandian, Jinyu Tian
In addition, due to the avoidance of using surrogate models' gradient information when optimizing AEs for black-box models, our proposed DifAttack inherently possesses better attack capability in the open-set scenario, where the training dataset of the victim model is unknown.