about the trigger
Guncuke opened this issue · comments
volcano commented
Hello author!
when I run this code, I found that the number of the tigger is out of 0~255, Is this normal? thanks!
Yugeng Liu commented
It is normal. We didn't do any regularization about the values.
volcano commented
thanks
volcano commented
I found that on the normalized image dataset, the final trigger even reached 1000+, which is high enough to get an accuracy of 100 even without top-k fine-tuning
Yugeng Liu commented
Yes, maybe this is a reason, but you can regularize the trigger in a range and see the ASR results.