Supplementary Material: Efficient and Effective Augmentation Strategy for Adversarial Training
–Neural Information Processing Systems
Base refers to the augmentations Pad+Crop+HFlip.Natural/ Adversarial Distributions Low-level distance Feature-level distance Natural images Base, Unaugmented Low Low Autoaugment, Unaugmented High Medium Adversarial images Base, Unaugmented Low Medium Autoaugment, Unaugmented High High
Neural Information Processing Systems
Oct-2-2025, 00:46:07 GMT
- Technology: