@wuxin1994 2017-11-26T14:40:22.000000Z 字数 1519 阅读 552

# 吴帆1126

学习笔记17

Conclusion: This technique, however, suffers from the high cost to generate adversarial examples and (at least) doubles the training cost of DNN models due to its iterative re-training procedure. It is essential to include adversarial examples produced by all known attacks in adversarial training, since this defensive training is non-adaptive. But, it is computationally expensive to find adversarial inputs by most known techniques, and there is no way to be confident the adversary is limited to techniques that are known to the trainer.

• 私有
• 公开
• 删除