diff --git a/INSTRUCTIONS.md b/INSTRUCTIONS.md index 58568ed..2fe6890 100644 --- a/INSTRUCTIONS.md +++ b/INSTRUCTIONS.md @@ -65,7 +65,7 @@ Note: 1. As mentioned in the paper, the threat model is: - 1. __Targeted attack__, with one target label associated with each image. The target lable is + 1. __Targeted attack__, with one target label associated with each image. The target label is independently generated by uniformly sampling the incorrect labels. 2. Maximum perturbation per pixel is 16.