2025
First Line of Defense: A Robust First Layer Mitigates Adversarial Attacks
AAAI 2025technical
Adversarial training (AT) incurs significant computational overhead, leading to growing interest in designing inherently robust architectures. We demonstrate that a carefully designed first layer of the neural network can serve as an implicit adversarial noise filter (ANF). This filter is created us…