no code implementations • 18 Dec 2023 • Zebin Yun, Achi-Or Weingarten, Eyal Ronen, Mahmood Sharif
We also found that the best composition significantly outperformed the state of the art (e. g., 93. 7% vs. $\le$ 82. 7% average transferability on ImageNet from normally trained surrogates to adversarially trained targets).