ScaleCert: Scalable Certified Defense against Adversarial Patches with Sparse Superficial Layers Husheng Han
–Neural Information Processing Systems
The key difference between the adversarial example attack and patch attack is the constraint of perturbation.
Neural Information Processing Systems
Nov-16-2025, 00:52:55 GMT