1 code implementation • NeurIPS 2021 • Ameya D. Patil, Michael Tuttle, Alexander G. Schwing, Naresh R. Shanbhag
Classical adversarial training (AT) frameworks are designed to achieve high adversarial accuracy against a single attack type, typically $\ell_\infty$ norm-bounded perturbations.