RandomNormalizationAggregationfor AdversarialDefense

Neural Information Processing Systems 

Traditionally, this transferability is always regarded as a critical threat to the defense against adversarial attacks, however, we argue that the network robustness can be significantly boosted by utilizing adversarial transferability from anewperspective.