Goto

Collaborating Authors

 Banff











On the Role of Randomization in Adversarially Robust Classification

Neural Information Processing Systems

Deep neural networks are known to be vulnerable to small adversarial perturbations in test data. To defend against adversarial attacks, probabilistic classifiers have been proposed as an alternative to deterministic ones. However, literature has conflicting findings on the effectiveness of probabilistic classifiers in comparison to deterministic ones.