Skip to main content

Table 11 Attack success rate of with (w.) and without (w.o.) shifted mean and std on three benchmark datasets under noise budget \(\epsilon =8\) and \(\epsilon =16\)

From: DTA: distribution transform-based attack for query-limited scenario

\(\epsilon\)

CIFAR-10

SVHN

ImageNet

w.o.

w.

w.o.

w.

w.o.

w.

8

13.92

73.57

18.64

55.36

17.83

44.21

16

31.33

80.49

48.76

84.11

40.19

71.68