Models trained with our attack achieve state-of-the-art robustness against white- box gradient-based L2 attacks on the MNIST and CIFAR-10 datasets, ...
確定! 回上一頁