Improving the robustness of adversarial attacks using an affine-invariant gradient estimator

Published: 01 Jan 2023, Last Modified: 04 Oct 2025Comput. Vis. Image Underst. 2023EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Highlights•We introduce an attack framework to improve the affine invariance of attack.•We design a gradient estimator to improve the efficiency of our algorithm.•Physical experiments show the robustness of our attack to complex transformations.•Our attack can serve as a good initialization for the query-based black-box attacks.
Loading