|
|
|
|
|
by eroccatlun
3152 days ago
|
|
Does the adversarial attack require access to the model making the predictions? It seems like the attack relies on `doping` the input with features present in a different target, or by masking features of the existing target. Could you so specifically attack a target without knowledge of its features? |
|