f56d8183992b6c54c92c16a8519a6e2b-AuthorFeedback.pdf
–Neural Information Processing Systems
Clean and robust error on the test set under various adversarial attacks. Specifically, for example, 28. 25(47) stands for 28 .25 0 . We thank the reviewers for their constructive comments. The requested additional experiments are presented above. Gradient scattering is measured as the first-order gradient difference, i.e., The architecture of our MNIST models are the same as the ones in the challenge.
Neural Information Processing Systems
Nov-15-2025, 16:08:40 GMT
- Technology: