On Norm-Agnostic Robustness of Adversarial Training On Norm-Agnostic Robustness of Adversarial Training Li, Bai and Chen, Changyou and Wang, Wenlin and Carin, Lawrence 2019

Paper summary

davidstutz

Li et al. evaluate adversarial training using both $L_2$ and $L_\infty$ attacks and proposes a second-order attack. The main motivation of the paper is to show that adversarial training cannot increase robustness against both $L_2$ and $L_\infty$ attacks. To this end, they propose a second-order adversarial attack and experimentally show that ensemble adversarial training can partly solve the problem. Also find this summary at [davidstutz.de](https://davidstutz.de/category/reading/).