On Norm-Agnostic Robustness of Adversarial Training
Li, Bai
and
Chen, Changyou
and
Wang, Wenlin
and
Carin, Lawrence
arXiv e-Print archive - 2019 via Local Bibsonomy
Keywords:
dblp
Li et al. evaluate adversarial training using both $L_2$ and $L_\infty$ attacks and proposes a second-order attack. The main motivation of the paper is to show that adversarial training cannot increase robustness against both $L_2$ and $L_\infty$ attacks. To this end, they propose a second-order adversarial attack and experimentally show that ensemble adversarial training can partly solve the problem.
Also find this summary at [davidstutz.de](https://davidstutz.de/category/reading/).