From: DTA: distribution transform-based attack for query-limited scenario
Metric | Model | 100 | 200 | 300 | 400 | 500 |
---|---|---|---|---|---|---|
ASR | ViT-16 | 29.93 | 33.04 | 35.16 | 35.91 | 37.53 |
ViT-32 | 34.35 | 38.08 | 39.28 | 40.61 | 41.01 | |
Swin-B | 26.63 | 29.35 | 29.23 | 30.77 | 31.48 | |
Avg.Q | ViT-16 | 15.59 | 2.89 | 40.50 | 49.03 | 60.91 |
ViT-32 | 13.79 | 24.58 | 34.24 | 41.51 | 43.57 | |
Swin-B | 17.00 | 29.83 | 36.35 | 48.08 | 56.22 |