Thwarting finite difference adversarial attacks with output randomization

Open in new window