no code implementations • AAAI Workshop AdvML 2022 • Nils Worzyk, Stella Yu
Using B-AT instead of AT for supervised learning, we can increase the robustness by 0. 56\% for small seen attacks.
no code implementations • 29 Sep 2021 • Nils Worzyk
When combining a larger corpus of input data with our proposed method, we report an increase of the clean accuracy and for all observed attacks, compared to AT.