Abstract
We propose a powerful second-order attack method that outperforms existing attack methods on reducing the accuracy of state-of-the-art defense models based on adversarial training. The effectiveness of our attack method motivates an investigation of provable …
Original language | Undefined/Unknown |
---|---|
Journal | arXiv preprint arXiv:1809.03113 |
State | Published - 2018 |
Externally published | Yes |