Abstract: In the field of text recognition models, existing adversarial attack algorithms mainly target white-box scenarios, which are usually limited to single-color backgrounds and short text length ...