(no title)
akhundelar | 4 years ago
What I had in mind when referring to 'basic evasion' was 'cropping or rotating', as per your original comment.
All that being said, I admit that generating adversarial examples for models with known weights is not a difficult task.
No comments yet.