ExploitingtheRelationshipBetweenKendall'sRank CorrelationandCosineSimilarityforAttribution Protection

Neural Information Processing Systems 

Our analysis further exposes that IGR encourages neurons with the same activation states for natural samples and the corresponding perturbed samples.