Supplementary Materials: Patch-wise Attack for Fooling Deep Neural Network

Lianli Gao,Qilong Zhang,Jingkuan Song,Xianglong Liu,Heng Tao,Shen
2020-01-01
Abstract:In this section, we show the results of difference project factor γ settings. For the following tables, the amplification factor β and project kernel Wp are fixed to the same settings mentioned in our paper. As shown in Tab. 1,2,3,4,5,6, setting the project factor γ to /T · β is the best choice in most cases. Besides, it is better not to use large project factor for attack methods with input diversity strategy, and if we use Res152B as our substitute model to attack against feature denoising models, setting γ to 1.0 is better.
What problem does this paper attempt to address?