Random Normalization Aggregation for Adversarial Defense (Supplementary Material)

Neural Information Processing Systems 

For a fair comparison, we consider two different attack settings. We take ResNet-18 and WideResNet32 as the models for evaluation. The detailed results are shown in Table 1 and 2. Our proposed RNA achieves better Thus, the number of attack iterations can be different for different examples. The comparison under this adaptive attack setting is provided in Table 3. Similarly, we include ResNet-18 and WideResNet32 for comparison on CIFAR-10/100.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found