Supplementary Materials of Drawing Robust Scratch Tickets: Subnetworks with Inborn Robustness Are Found within Randomly Initialized Networks

Neural Information Processing Systems 

We evaluate the identified RSTs' robustness against more attacks on top of two networks on CIFAR-10 as a complement for Sec. As observed from Tab. 1, we can see that the RSTs searched by PGD-7 training are also robust against other attacks. As observed in Figure 1, RSTs drawn from randomly initialized networks achieve a comparable natural accuracy with the RTTs drawn from naturally/adversarially trained networks and adversarial RTTs generally achieve the best natural accuracy. Trained), (2) adversarially trained dense models (Dense Adv. Trained 70.70 74.35 77.20 77.71 75.55 79.22 78.85 77.33 0 81.28 Dense Adv.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found