← Search

Zhaozhe Hu

2 accepted papers

2025

KOEnsAttack: Towards Efficient Data-Free Black-Box Adversarial Attacks via Knowledge-Orthogonalized Substitute Ensembles

ICCV 2025poster

Data-free black-box attacks aim to attack a model without access to either the model parameters or training data. Existing methods use a generator to synthesize training samples and then train a substitute model to imitate the victim model. The adversarial examples (AEs) are finally generated using…

Cited by 0SourcePDFScholar
2024

MEAT: Median-Ensemble Adversarial Training for Improving Robustness and Generalization

ICASSP 2024accepted

Self-ensemble adversarial training methods improve model robustness by ensembling models at different training epochs, such as model weight averaging (WA). However, previous research has shown that self-ensemble defense methods in adversarial training (AT) still suffer from robust overfitting, which…

Cited by 0SourceScholar