Adversarial Examples Exist in Two-Layer ReLU Networks for Low Dimensional Linear Subspaces

Open in new window