[R] Adversarial Training with Voronoi Constraints
We analyze adversarial examples using techniques from high-dimensional geometry. We demonstrate several problems with the standard formulation of adversarial training using Lp-balls centered on the data, which occur in high-dimensional space. From these insights, we propose a new geometric constraint to replace the Lp-balls which gives improved robustness in some settings.
I’m the lead author of this article and would be happy to answer any questions!