On the Limitations of Stochastic Pre-processing Defenses

Neural Information Processing Systems 

Defending against adversarial examples remains an open problem. A common belief is that randomness at inference increases the cost of finding adversarial inputs. An example of such a defense is to apply a random transformation to inputs prior to feeding them to the model.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found