Thanks for the open-source of your neurips23 paper Rethinking the Backward Propagation for Adversarial Transferability!
While I try to reproduce the results in Table 3 -- defense methods evaluation of BPA. I found the model files for defense methods HGD and NRP are not provided in this code repository.
It would be very helpful if you could provide these two files.
Dear authors,
Thanks for the open-source of your neurips23 paper Rethinking the Backward Propagation for Adversarial Transferability!
While I try to reproduce the results in Table 3 -- defense methods evaluation of BPA. I found the model files for defense methods HGD and NRP are not provided in this code repository.
It would be very helpful if you could provide these two files.
Thank you!