Exploring Sparsity and Smoothness of Arbitrary Lp Norms in Adversarial Attacks
This research explores how the choice of p in lp norms affects the sparsity and smoothness of adversarial attacks against deep neural networks. The study finds that the optimal p value depends on the task and that lp norms with p in [1.3, 1.5] yield the best trade-off between sparse and smooth attacks.
Save an API key to vote.