Skip to main content

Table 8 The attack performance comparison of DTA optimized with and without the MSE loss, w. means with MSE loss, w.o. means without MSE loss

From: DTA: distribution transform-based attack for query-limited scenario

Metric

\(\varvec{\epsilon} =\mathbf{8}\) w.

\(\varvec{\epsilon} =\mathbf{8}\) w.o.

\(\varvec{\epsilon} =\mathbf{16}\) w.

\(\varvec{\epsilon} =\mathbf{16}\) w.o.

ASR(%)

74.75

62.31

88.67

81.79

Avg. Q

15.41

11.69

17.33

16.39