The limitations of adversarial training and the blind-spot attack
The adversarial training procedure proposed by Madry et al. (2018) is one of the most effective methods to defend against adversarial examples in deep neural networks (DNNs). In our paper, we shed some lights on the practicality and the hardness of adversarial training by showing that the effectiven...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Article |
Language: | English |
Published: |
ICLR,
2021-03-05T11:58:35Z.
|
Subjects: | |
Online Access: | Get fulltext |