New computational algorithms make it possible to build neural networks with many input nodes and many layers, and distinguish "deep learning" of these networks from previous work on artificial neural nets.
The above-mentioned pooling methods are generally described by a convex-hull model which produces the output activation as a convex combination of the input neuron activations (Section 2.1).
While many techniques for detecting these attacks have been proposed, they are easily bypassed when the adversary has full knowledge of the detection mechanism and adapts the attack strategy accordingly.