From: DTA: distribution transform-based attack for query-limited scenario
Metric | \(\varvec{\epsilon} =\mathbf{8}\) w. | \(\varvec{\epsilon} =\mathbf{8}\) w.o. | \(\varvec{\epsilon} =\mathbf{16}\) w. | \(\varvec{\epsilon} =\mathbf{16}\) w.o. |
---|---|---|---|---|
ASR(%) | 74.75 | 62.31 | 88.67 | 81.79 |
Avg. Q | 15.41 | 11.69 | 17.33 | 16.39 |