1 code implementation • 6 May 2020 • Zifan Wang, Yilin Yang, Ankit Shrivastava, Varun Rawal, Zihao Ding
We show that the vulnerability of the model against tiny distortions is a result of the model is relying on the high-frequency features, the target features of the adversarial (black and white-box) attackers, to make the prediction.