REVIEW 2 cited by
Defensive Distillation is Not Robust to Adversarial Examples
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
We show that defensive distillation is not secure: it is no more resistant to targeted misclassification attacks than unprotected neural networks.
Forward citations
Cited by 2 Pith papers
-
Evaluating the Robustness of the "Ensemble Everything Everywhere" Defense
Adaptive attacks reduce the robust accuracy of the 'Ensemble Everything Everywhere' defense to 11% on CIFAR-10 and 14% on CIFAR-100 under an l-infinity bound of 8/255.
-
Improving the Robustness/Accuracy Tradeoff Against Adversarial Attacks Using Information Bottleneck Distillation Through Dual Teachers
Adding a clean teacher to Information Bottleneck Distillation raises clean accuracy by about 0.8 points on CIFAR data while holding robust accuracy nearly steady.
Discussion (0). Continue with ORCID to comment.