5,321
edits
No edit summary |
|||
Line 9: | Line 9: | ||
==Defenses== | ==Defenses== | ||
Most defenses focus on generating adversarial examples during training time and training on those adversarial examples.<br> | |||
Below are some alternatives to this approach. | |||
===Interval Bound Propagation=== | ===Interval Bound Propagation=== | ||
Interval Bound Propagation (IBP)<br> | Interval Bound Propagation (IBP)<br> | ||
[https://arxiv.org/abs/1810.12715 A paper] | [https://arxiv.org/abs/1810.12715 A paper] |