Random Normalization Aggregation for Adversarial Defense (Supplementary Material)
–Neural Information Processing Systems
For a fair comparison, we consider two different attack settings. We take ResNet-18 and WideResNet32 as the models for evaluation. The detailed results are shown in Table 1 and 2. Our proposed RNA achieves better Thus, the number of attack iterations can be different for different examples. The comparison under this adaptive attack setting is provided in Table 3. Similarly, we include ResNet-18 and WideResNet32 for comparison on CIFAR-10/100.
Neural Information Processing Systems
Aug-19-2025, 08:50:10 GMT
- Technology: