We also apply PGD-1 and PGD-2 w/wo FN to attack a standard WRN-34-10 model, and PGD-1 (s, m): Heuristically, the value range of s is based on the averaged logit norms of standard
–Neural Information Processing Systems
We thank all the reviewers for their valuable comments. Below, we address the detailed comments of each reviewer. The margin range m is chosen to be around cos 30 0.15. Then other samples that are not well-learned will dynamically contribute more. Figure 1, Sec. 3.5, and other comments: Thank you for the suggestions.
Neural Information Processing Systems
May-21-2025, 05:58:17 GMT
- Technology: