1 paper
Odelia Melamed, Gilad Yehudai, Adi Shamir
Current adversarial attacks for multi-class classifiers choose the target class for a given input naively, based on the classifier's confidence levels for various target classes. W…