Goto

Collaborating Authors

 Technology



RandomNormalizationAggregationfor AdversarialDefense

Neural Information Processing Systems

Traditionally, this transferability is always regarded as a critical threat to the defense against adversarial attacks, however, we argue that the network robustness can be significantly boosted by utilizing adversarial transferability from anewperspective.




57bafb2c2dfeefba931bb03a835b1fa9-AuthorFeedback.pdf

Neural Information Processing Systems

Details of the layers can be found in the supplement Table S.2. We will add another, larger figure illustrating the18 U-shape and thethree parts ofthearchitecture. Thesleepstage23 scores indeed show human interpretable patterns even on short timescales. We regard it as a big41 advantage thatwedidnotextensivelytune ourarchitec-42 ture to the tasks. Wewill improvethe colour palette as suggested.