Is there any pretrained model for epsilon=16/255 available? Does such strong attack make resnet50 too terrible on benign examples?
BTW, according to readme: (Have you used the package and found it useful? Let us know!).
The code is a good reference, but more importantly the pretrained imagenet model is very much appreciated! Cost of standard adversarial training on imagenet is just hard to accept for most researchers in this field.
Is there any pretrained model for epsilon=16/255 available? Does such strong attack make resnet50 too terrible on benign examples?
BTW, according to readme:
(Have you used the package and found it useful? Let us know!).
The code is a good reference, but more importantly the pretrained imagenet model is very much appreciated! Cost of standard adversarial training on imagenet is just hard to accept for most researchers in this field.