1 paper
Yu-Yu Wu, Hung-Jui Wang, Shang-Tse Chen
In standard adversarial training, models are optimized to fit one-hot labels within allowable adversarial perturbation budgets. However, the ignorance of underlying distribution sh…