Abstract: Highlights•Black-box sensitivity maps are transferable between different models.•Dynamic lp norm adjustment and adaptive evolution strategy promotes attack.•Proposed SRA can generate imperceptible and interpretable adversarial examples.
Loading