For black-box attacks, the gap between substitute model and victim is usually large, which manifests as a weak attack performance. Motivated by observation that transferability of adversarial examples can be improved attacking diverse models simultaneously, augmentation methods simulate different using transformed images are proposed. However, existing transformations for spatial domain do not ...