Many defenses against adversarial attacks (e.g., robust classifiers, randomization, or image purification) use countermeasures put to work only after the attack has been crafted. We adopt a different perspective to introduce
To facilitate the distribution and use of the code among researchers, we suggest using docker:
Detailed information about
Please cite our work as:
@inproceedings{Fro23_a5,
author={Frosio, Iuri and Kautz, Jan},
year={2023},
title={The Best Defense is a Good Offense: Adversarial Agumentation Against Adversarial Attacks},
booktitle={CVPR},
}