3

Query-Free Adversarial Transfer via Undertrained Surrogates

We find that transferability of adversarial attacks can be substantially improved by using a surrogate model which is not fully trained.