Closed davidslater closed 2 years ago
This can be accomplished by performing a PGD-style attack on each training sample (in a batch). Since this will generate concrete examples, it will provide a lower bound on the local sensitivity for that batch.
This can be accomplished by performing a PGD-style attack on each training sample (in a batch). Since this will generate concrete examples, it will provide a lower bound on the local sensitivity for that batch.