##Illustration

- defense_xxx_ppp.py: codes for evaluating the defense performance agasint black-box attak, where xxx means the attacks methods used to evaluate, ppp corresponding the section in the paper. For example, defense_pgd_sota means evaluating the defense performance agasint pgd attack for Section 4.1.1 in the paper.
