Dear author, the findings in your paper is quite interesting. However, I am still confused about the purpose of this paper. In Introduction section, you said "However, given that the adversary has full access to the input x, apriori there is no reason to restrict the perturbations to only the pixel representations." Does any existing works have shown that, AEs generated on pixel-image trained model has a poor transferability performance to those frequency-image trained models? I would be grateful if you could answer my questions. Thanks!
Dear author, the findings in your paper is quite interesting. However, I am still confused about the purpose of this paper. In Introduction section, you said "However, given that the adversary has full access to the input x, apriori there is no reason to restrict the perturbations to only the pixel representations." Does any existing works have shown that, AEs generated on pixel-image trained model has a poor transferability performance to those frequency-image trained models? I would be grateful if you could answer my questions. Thanks!