[paper]ADVERSARIAL REPROGRAMMING OF NEURAL NETWORKS

传统对抗样本目的是使模型分类错误,本文通过则是使模型执行特定任务(攻击者设定),且该任务可以未被训练过。 We introduce attacks that instead reprogram the target model to perform a task chosen by the attacker—without the attacker needing to specify or co
相关文章
相关标签/搜索