evaluating-adversarial-robustness/adv-eval-paper
LaTeX source for the paper "On Evaluating Adversarial Robustness"
TeX
Issues
- 2
- 0
- 7
Amending papers after attack
#26 opened by ftramer - 0
Recommend evaluating over just 100-1000 examples
#28 opened by carlini - 1
Don't recommend transfer attacks (controversial)
#27 opened by carlini - 1
Decomposing improvements in accuracy
#24 opened by yaoshiang - 5
Impact and remaining misconceptions
#22 opened by ftramer - 1
- 1
Studying robustness wrt. other attacks, distal adversarial examples, details of success rate computation, evaluation of detection methods
#15 opened by davidstutz - 2
Do not use number of iterations of attack required as a measure of robustness
#18 opened by anishathalye - 1
Emphasize Random Restarts in Evaluation
#19 opened by hendrycks - 12
road signs threat model
#4 opened by earlenceferns - 0
Don't optimize one thing but measure another
#17 opened by anishathalye - 4
References missing in PDF on GitHub
#6 opened by jonasrauber - 7
- 2
Misclassification as malware is fun
#12 opened by adamshostack - 6
Third property of secrets
#2 opened by dxoigmn