Fig. 1From: DTA: distribution transform-based attack for query-limited scenarioThe framework of the Distribution transform-based attack. \(\varvec{X}'\) is the adversarial space characterized by the collected adversarial examples and \(\varvec{X}\) is the space of the corresponding original clean examples. The hidden space \(\varvec{Z}\) follows a simple Gaussian distributionBack to article page