Hi and thanks for the open source. I am very interested in your paper. I have some questions.
Excuse me, does the loss function used in training the simulator and the loss function used in the simulator attack have to be the same?
Can I use a targeted attack while training the simulator and an untargeted attack while the simulator is attacking?