Hacker News new | ask | show | jobs
by ipsa 2785 days ago
You can try out this technique at https://github.com/google/unrestricted-adversarial-examples My guess is it would have the same result as adding noise to the normal images too (resulting in a slightly worse performance overall).