e6ff107459d435e38b54ad4c06202c33-Supplemental.pdf

Neural Information Processing Systems 

Supplementary Material: Can we have it all? This section provides the proof for Proposition 1. We now prove Theorem 2 on the trade-off between spatial and adversarial robustness. Now if the adversarial robustness (i.e., the LHS above) is at least The other side of the trade-off can be proved similarly. F or m = d/ 2, this accuracy is as bad as that of a random classifier .

Similar Docs  Excel Report  more

TitleSimilaritySource
None found