Supplementary Material for Understanding and Improving Ensemble Adversarial Defense
–Neural Information Processing Systems
They are used to test the proposed enhancement approach iGA T. In general, ADP employs an ensemble by averaging, i.e., (C 1) ( C 1) Adversarial examples are generated to compute the losses by using the PGD attack. Our main theorem builds on a supporting Lemma 2.1. We start from the cross-entropy loss curvature measured by Eq. The above new expression of T (x) helps bound the difference between h(x) and h(x). Note that these three cases are mutually exclusive.
Neural Information Processing Systems
Feb-16-2026, 16:46:47 GMT