You state that: the two networks don’t process images in the same way and thus cannot be manipulated to misclassify them using the same techniques.
But the job posting states that one of the project goals is to determine: “Are the principles of adversarial attacks on BNNs different from those on [artificial neural…