Without Learning Rate Resets
–Neural Information Processing Systems
Clean and robust error on the test set under various adversarial attacks. The numbers between the brackets indicate the standard deviation across different runs. Specifically, for example, 28.25(47) stands for 28.25 0.47. We thank the reviewers for their constructive comments. The table above shows that our PAS strategy still yields better performance under stronger attacks.
Neural Information Processing Systems
Mar-21-2025, 21:31:09 GMT
- Technology: