no code implementations • ICML Workshop AML 2021 • Benjamin Spetter-Goldstein, Nataniel Ruiz, Sarah Adel Bargal
We also show how the $\ell_2$ norm and other metrics do not correlate with human perceptibility in a linear fashion, thus making these norms suboptimal at measuring adversarial attack perceptibility.