Research Article

FAPA: Transferable Adversarial Attacks Based on Foreground Attention

Algorithm 1

Input: The loss function of equation (2), a white-box model , a clean image with its ground-truth class , model, , , the perturbation budget , iteration number , used patch number .
Output: The adversarial example .
(1)
(2)
(3)fordo
(4)ifthen
(5)  ,
(6)  ←equation (2),
(7)ifthen
(8)  ,
(9)   equation (2),
(10)ifthen
(11)  ,
(12)   equation (2),
(13)
(14)
(15)
(16)