Closed paullintilhac closed 2 years ago
Does this mean we're using a sub-optimal attack for all defenses? Need to make sure we're calling the gradient_transform function properly.
this is an old question, I don't think I was understanding the code properly. This was probably the first stage where it was running the undefended model.
Does this mean we're using a sub-optimal attack for all defenses? Need to make sure we're calling the gradient_transform function properly.