no code implementations • 19 Sep 2020 • Ya-guan Qian, Qiqi Shao, Jia-min Wang, Xiang Lin, Yankai Guo, Zhaoquan Gu, Bin Wang, Chunming Wu
This dynamic defense can prohibit the adversary from selecting an optimal substitute model for black-box attacks.