C Xie, J Wang, Z Zhang, Z Ren, A Yuille - cihangxie.github.io
Let x denote the input image; Let f denote the a classifier, eg, a neural network; Let l denote
the adversarial label, ie, f (x)≠ l To find the adversarial perturbation r, we can solve the …