no code implementations • 29 Sep 2021 • Itai Mesery, Dana Drachsler Cohen
We leverage ideas from program synthesis and numerical optimization to search in this large, discrete space and obtain attacks that are competitive with the C&W attack but have at least 3x and up to 10x fewer perturbed pixels.