Characterizing the Optimal $0-1$ Loss for Multi-class Classification with a Test-time Attacker
Finding classifiers robust to adversarial examples is critical for their safe deployment. Determining the robustness of the best possible classifier under a given threat model for a fixed data distribution and comparing it to that achieved by state-of-the-art training methods is thus an important di…