e6ff107459d435e38b54ad4c06202c33-Supplemental.pdf
–Neural Information Processing Systems
Supplementary Material: Can we have it all? This section provides the proof for Proposition 1. We now prove Theorem 2 on the trade-off between spatial and adversarial robustness. Now if the adversarial robustness (i.e., the LHS above) is at least The other side of the trade-off can be proved similarly. F or m = d/ 2, this accuracy is as bad as that of a random classifier .
Neural Information Processing Systems
Nov-15-2025, 23:28:44 GMT