PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning
Patch-based attacks introduce a perceptible but localized change to the input that induces misclassification. A limitation of cur- rent patch-based black-box attacks is that they perform poorly for tar- geted attacks, and even for the less challenging non-targeted scenarios, they require a large number of queries.