I’m not sure what those or earlier results mean, practically speaking. And the increased use of data augmentation may mean that the newer neural networks don’t show that behavior, pace those papers showing it’s useful to add the adversarial examples to the training sets.
I’m not sure what those or earlier results mean, practically speaking. And the increased use of data augmentation may mean that the newer neural networks don’t show that behavior, pace those papers showing it’s useful to add the adversarial examples to the training sets.