ec20019911a77ad39d023710be68aaa1-Supplemental.pdf
–Neural Information Processing Systems
From the results, we can see that AdvBN alone can improve the baseline model on all corruption types. Models of all methods are implemented based on ResNet-50 and trained on the original ImageNet training set. The default setting of our method on ResNet-50 uses 6 PGD steps, so the training time is longer than standard training for the same number of epochs.
Neural Information Processing Systems
Feb-11-2026, 18:18:27 GMT
- Technology: