REVIEW 1 cited by
On Norm-Agnostic Robustness of Adversarial Training
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
abstract
Adversarial examples are carefully perturbed in-puts for fooling machine learning models. A well-acknowledged defense method against such examples is adversarial training, where adversarial examples are injected into training data to increase robustness. In this paper, we propose a new attack to unveil an undesired property of the state-of-the-art adversarial training, that is it fails to obtain robustness against perturbations in $\ell_2$ and $\ell_\infty$ norms simultaneously. We discuss a possible solution to this issue and its limitations as well.
Forward citations
Cited by 1 Pith paper
-
Ensemble Distribution Distillation for Self-Supervised Human Activity Recognition
A single prior network distilled from a 50-member self-supervised ensemble matches ensemble accuracy and robustness on HAR benchmarks at single-model inference cost.
Discussion (0). Continue with ORCID to comment.