← Search

Huan Zhang*

2 accepted papers

2019

The Limitations of Adversarial Training and the Blind-Spot Attack

ICLR 2019poster

The adversarial training procedure proposed by Madry et al. (2018) is one of the most effective methods to defend against adversarial examples in deep neural net- works (DNNs). In our paper, we shed some lights on the practicality and the hardness of adversarial training by showing that the effectiv…

Cited by 194SourcePDFScholar
2018

Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach

ICLR 2018poster

The robustness of neural networks to adversarial examples has received great attention due to security implications. Despite various attack approaches to crafting visually imperceptible adversarial examples, little has been developed towards a comprehensive measure of robustness. In this paper, we p…