Tuscany
- Europe > United Kingdom > England > Greater London > London (0.05)
- Europe > Italy > Tuscany > Florence (0.04)
- Europe > Germany (0.14)
- Asia > China (0.14)
- North America > Canada > British Columbia (0.04)
- (12 more...)
- Law > Statutes (1.00)
- Law > Litigation (1.00)
- Law > Civil Rights & Constitutional Law (1.00)
- (5 more...)
- North America > United States > Minnesota > Hennepin County > Minneapolis (0.14)
- Europe > Belgium > Brussels-Capital Region > Brussels (0.05)
- Europe > Russia (0.04)
- (6 more...)
- North America > United States > Minnesota > Hennepin County > Minneapolis (0.14)
- North America > United States > Texas > Travis County > Austin (0.04)
- North America > United States > Hawaii > Honolulu County > Honolulu (0.04)
- (13 more...)
- North America > United States (0.67)
- South America > Colombia > Meta Department > Villavicencio (0.04)
- North America > Canada (0.04)
- (4 more...)
- Health & Medicine > Therapeutic Area > Oncology (0.93)
- Health & Medicine > Therapeutic Area > Cardiology/Vascular Diseases (0.93)
- Education (0.93)
- (2 more...)
- Europe > Austria > Vienna (0.14)
- Europe > Germany (0.04)
- North America > United States > New York > New York County > New York City (0.04)
- (10 more...)
Appendices
The supplementary material is organized as follows. We first discuss additional related work and provide experiment details inSection 2andAppendix Brespectively. Adversarial Defenses: Neural networks trained using standard procedures such as SGD are extremely vulnerable [23] to -bound adversarial attacks such as FGSM [23], PGD [42], CW [11], andMomentum [17];Unrestricted attacks [7,19]cansignificantly degrade model performance as well. Defense strategies based on heuristics such as feature squeezing [82], denoising [80], encoding [10], specialized nonlinearities [83] and distillation [56] have had limited success against stronger attacks [2]. Then, we introduce a noisy version of the5-slab block,whichwelateruseinAppendixD.
6cfe0e6127fa25df2a0ef2ae1067d915-Paper.pdf
However,maximum-marginclassifiers areinherently robusttoperturbations ofdata at prediction time, and this implication is at odds with concrete evidence that neural networks, in practice, are brittle toadversarial examples [71]and distribution shifts [52,58,44,65]. Hence, the linear setting, while convenient to analyze, is insufficient to capture the non-robustness of neural networkstrainedonrealdatasets.Goingbeyondthelinearsetting,severalworks[ 1,49,74]arguethat neuralnetworksgeneralize wellbecause standard training procedures haveabiastowardslearning
- North America > United States > California > Santa Clara County > Palo Alto (0.04)
- North America > Canada > British Columbia > Metro Vancouver Regional District > Vancouver (0.04)
- Europe > Italy > Tuscany > Florence (0.04)
- Asia > Japan > Honshū > Kantō > Tokyo Metropolis Prefecture > Tokyo (0.15)
- Oceania > Australia > New South Wales > Sydney (0.04)
- North America > United States > New York > Richmond County > New York City (0.04)
- (11 more...)