📢 Check out our new report: we show that a recently proposed defense against adversarial attacks is not robust. We circumvent gradient masking issues of the proposed model by attacking a slightly adapted surrogate model and then transferring the perturbations.
about 1 year ago