5 code implementations • NeurIPS 2019 • Bao Wang, Binjie Yuan, Zuoqiang Shi, Stanley J. Osher
However, both natural and robust accuracies, in classifying clean and adversarial images, respectively, of the trained robust models are far from satisfactory.