1 paper
Chizhou Liu, Yunzhen Feng, Ranran Wang +1
Randomized smoothing has achieved state-of-the-art certified robustness against l2-norm adversarial attacks. However, it is not wholly resolved on how to find the optimal base c…