Understanding and Improving Ensemble Adversarial Defense

Neural Information Processing Systems 

Guided by this theory, we propose an effective approach to improve ensemble adversarial defense, named interactive global adversarial training (iGA T).