Dear teacher, I am a student studying adversarial samples, may I ask that the adversarial examples generated by your library do not have the ability to generalize, what is the reason, and is it my fault? For example, the FGSM method cannot fool a retrained network.
Hope to get your answer,thank you very much!
Dear teacher, I am a student studying adversarial samples, may I ask that the adversarial examples generated by your library do not have the ability to generalize, what is the reason, and is it my fault? For example, the FGSM method cannot fool a retrained network. Hope to get your answer,thank you very much!
FGSM_.zip