Hacker News new | ask | show | jobs
by eroccatlun 3152 days ago
Does the adversarial attack require access to the model making the predictions?

It seems like the attack relies on `doping` the input with features present in a different target, or by masking features of the existing target.

Could you so specifically attack a target without knowledge of its features?