Thanks for your awesome lib. When I use your code, I find that the attack module requires the input images to be in the range of [0,1]. Does it mean that the model to be attacked has to be trained with the input with a range of [0,1]? What if I have a model that is trained with images that are augmented? Is there a way to include the image transformation into the attack process?
Hi Harry,
Thanks for your awesome lib. When I use your code, I find that the attack module requires the input images to be in the range of [0,1]. Does it mean that the model to be attacked has to be trained with the input with a range of [0,1]? What if I have a model that is trained with images that are augmented? Is there a way to include the image transformation into the attack process?
Best, Hao