5,337
edits
Line 628: | Line 628: | ||
We optimize <math>\min_{\theta} E \left[ l(f_{\theta}(x), y) \right] = \frac{1}{n} \sum l(f_{\theta}(x_i), y_i) </math>. | We optimize <math>\min_{\theta} E \left[ l(f_{\theta}(x), y) \right] = \frac{1}{n} \sum l(f_{\theta}(x_i), y_i) </math>. | ||
; | ;What is an ''adversarial example''? | ||
<math>x'</math> is an adversarial example for <math>x</math> under a model <math>f_{\theta}()</math> if | <math>x'</math> is an adversarial example for <math>x</math> under a model <math>f_{\theta}()</math> if | ||
* <math>f_{\theta}(x) \neq f_{\theta}(x')</math> and | * <math>f_{\theta}(x) \neq f_{\theta}(x')</math> and |