The epsilon-difference adversarial input problem seems like it could be solved by averaging lots of similar inputs. Is that just too computationally expensive?
The epsilon-difference adversarial input problem seems like it could be solved by averaging lots of similar inputs. Is that just too computationally expensive?