Skip to main content
. Author manuscript; available in PMC: 2021 Feb 28.
Published in final edited form as: Neurocomputing (Amst). 2019 Oct 31;379:370–378. doi: 10.1016/j.neucom.2019.10.085
Algorithm 4 l Attack for a batch of images
1input:a batchoforiginalimages{x0,x1,,xm},predictorF,lupper boundϵ,numberofiterationsN2output:adversarialperturbationΔx3t0,j04αϵN5whilej<N:6tt+αsign(i=0mF(xi+t))7jj+18Δxt