SMI-FGSM:空间动量提高对抗迁移性
2 相关工作fθ(xadv)≠y,s.t.∥xadv−x∥p≤ϵf_\theta(x^{adv})\ne y, \quad s.t. \quad \|x^{adv}-x\|_p\le \epsilonfθ(xadv)=y,s.t.∥xadv−x∥p≤ϵxadv=x+ϵ⋅sign(∇xJ(x,y))x^{adv}=x+\epsilon \cdot \mathrm{sign}(\nabla_x J(x,y))xadv=x+ϵ⋅sign(∇xJ(x,y))xt+1adv=xtadv+α⋅sign(