Thank you very much for sharing the SVRE code, I would like to know the results of your experiments on targeted metastatic black box attacks. We have recently produced a Pytorch version of SVRE and experimented in face recognition. We found that, on targeted transferability black-box attacks, the results of SVRE are much lower than Ens. We are not sure what caused this result, whether the problem was with the code we produced, or SVRE is only for untargeted.
Thank you very much for sharing the SVRE code, I would like to know the results of your experiments on targeted metastatic black box attacks. We have recently produced a Pytorch version of SVRE and experimented in face recognition. We found that, on targeted transferability black-box attacks, the results of SVRE are much lower than Ens. We are not sure what caused this result, whether the problem was with the code we produced, or SVRE is only for untargeted.