"All existing adversarial example attacks require knowledge of either the model internals, or its training data.
— 👩💻 Paige Bailey (@DynamicWebPaige) December 28, 2017
We introduce the first practical demonstration of an attacker controlling a remotely hosted DNN with no such knowledge — and our algorithm misclassifies *84.24%*." pic.twitter.com/lZyqX9jKNu
Leave a Reply