The diagram contains x 1, x 2 and x 3, with perturbed inputs x 1 plus delta 1, x 2 plus delta 2 and x 3 plus delta 3. All inputs pass through f theta into a latent representation space. The upper region contains f theta x 1, f theta x 2 and f theta x 3, each separated from its corresponding perturbed representation. Double-headed arrows connect each pair. An arrow labelled Adversarial Training leads to a second region. In this region, each f theta x input is positioned close to its corresponding f theta x plus delta representation.Illustration of perturbation invariance for the features after defense model through adversarial training
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.