1 code implementation • 26 Nov 2023 • Sitong Liu, Zhichao Lian, Shuangquan Zhang, Liang Xiao
Notably, the residual perturbations on the purified image primarily stem from the same-position patch and similar patches of the adversarial sample.
Adversarial Attack