Then, the trained discriminator 𝐷1D1 can be used as a surrogate model of the target model 𝑇T, and the overall structure of DDSG-GAN is shown in Figure 1. The input of Generator 𝐺G is the original image 𝑥x, and the output is perturbation vector 𝛿=𝐺(𝑥;𝜃𝑔)δ=...