Figure 10.
A diagram of adversarial training bringing latent representations of x 1, x 2 and x 3 closer to their perturbed counterparts.The diagram contains x 1, x 2 and x 3, with perturbed inputs x 1 plus delta 1, x 2 plus delta 2 and x 3 plus delta 3. All inputs pass through f theta into a latent representation space. The upper region contains f theta x 1, f theta x 2 and f theta x 3, each separated from its corresponding perturbed representation. Double-headed arrows connect each pair. An arrow labelled Adversarial Training leads to a second region. In this region, each f theta x input is positioned close to its corresponding f theta x plus delta representation.

Illustration of perturbation invariance for the features after defense model fθ through adversarial training

or Create an Account

Close Modal
Close Modal