Our aim is to improve adversarial robustness via an input which consists of multiple differently-perturbed variants of the original input, hopefully trading-off computation cost rather than accuracy for robustness. - View it on GitHub
Star
0
Rank
14121396