Closed boxin-wbx closed 3 years ago
Hi, sorry for the late reply, and thanks for your contribution! This is a really nice defense work based on the information bottleneck (IB) framework and gives me much inspiration. Glad to see a new defense direction besides typical adversarial training, certification (which optimizes an error bound on a local convert hull, you can also check it in our list :-) ), and input preprocessing (like robust encoding, perturbation recognizer, and so on).
Add one defense paper from ICLR 2021