adversarial examples, and demonstrate that there could be infinitely many such examples lying in convex polytopes

Neural Information Processing Systems 

We thank the reviewers for their feedback. All reviewers found the paper "interesting", and various reviewers commented that "the phenomenon identified here This can be also used to guide architecture selection. Thanks for the suggestion - the findings do hold approximately for any activation function that saturates, i.e. sigmoid, We will comment on this in the camera-ready. Thank you for your suggestion! For Sect. 4.1, the softmax is over just over the

Similar Docs  Excel Report  more

TitleSimilaritySource
None found