1 code implementation • 8 Apr 2023 • Senad Beadini, Iacopo Masi
Though a common assumption is that adversarial points leave the manifold of the input data, our study finds out that, surprisingly, untargeted adversarial points in the input space are very likely under the generative model hidden inside the discriminative classifier -- have low energy in the EBM.