Closed zjysteven closed 4 years ago
Sorry for late replay. I was busy these days.
We conducted some experiments on CIFAR-10, and SGM did work. For example, if we set a VGG-19 (with BatchNorm) as a target model (93.3% accuracy on CIFAR-10), its accuracy decreases to 10.57% after attacking using a ResNet-18 as a source model with SGM-based PGD-10 (eps=8/255, step-size=2/255), while 43.64% accuracy with vanilla PGD-10 using the same settings.
Hope that answered your question :)
Thanks for the response!
Hi, thanks for making the code available!
I'm just wondering if you have tested SGM on CIFAR-10 by any chance? And if so, does SGM still expose stronger transferability? Thanks!