Probabilistic Margins for Instance Reweighting in Adversarial Training

Neural Information Processing Systems 

Specifically, a PM is defined as the difference between two estimated class-posterior probabilities, e.g., such a probability of the true label minus the probability of