ftramer/ensemble-adv-training

About the convergence of adversarial training.

anonymous530 opened this issue · 0 comments

Hello. Thanks for your great work. May I ask, how to judge the convergence of adversarial training? Just according to the curve of loss?
As training going on, models become more robust. What if attack fails when training?