no code implementations • 6 Aug 2019 • Ravi Raju, Mikko Lipasti
First, we motivate the defense with a frequency analysis of the first layer feature maps of the network on the LISA dataset, which shows that high frequency noise is introduced into the input image by the $RP_2$ algorithm.