SupplementaryMaterial

Neural Information Processing Systems 

Now, adversarial perturbations on the data-generating distributionσ are a subset of perturbations generated by the classT. Moreover, the inequality is strict fort (0,1), from which it follows that the lossLσ is strictly convex. Let {f } [0,1] be a family of maps fromX to Y that is pointwise smooth (i.e., for anyx X, F(,x) = f (x)issmooth in). We see that F is closed, convex and bounded. Boundedness ofF follows from compactness of Y which implies that there exists anM R 0 such that Y BM(0Y). It follows that for any f F, we havek|f|kL (X,µ) M. Let {fn}n N be a minimizing sequence in F for the loss Lσ, such that fn F and limn Lσ(fn) = inff FLσ(f).

Similar Docs  Excel Report  more

TitleSimilaritySource
None found