no code implementations • 6 May 2021 • Peilin Kang, Seyed-Mohsen Moosavi-Dezfooli
In this paper, we find CO is not only limited to FGSM, but also happens in $\mbox{DF}^{\infty}$-1 adversarial training.