3ad7c2ebb96fcba7cda0cf54a2e802f5-Paper.pdf
–Neural Information Processing Systems
Adversarial training, as a general robustness improvement technique, eliminates the vulnerability in a single model by forcing it to learn robust features. The process is hard, often requires models with large capacity, andsuffersfrom significant lossonclean dataaccuracy.
Neural Information Processing Systems
Feb-8-2026, 03:36:40 GMT