
We construct robust source networks by performing adversarialtraining[21,45]. Baseline refers to the misclassification rate of unperturbed images. The adversarial perturbations are subject to an` constraint of16/255, and are optimized with the TMDI-FGSMalgorithm.