None
EN
A Discussion of 'Adversarial Examples Are Not Bugs, They Are Features': Robust Feature Leakage
['Goh']
Distill
Next, we train a linear classifier as per , Equation 3 on the datasets D ^ det \hat{\mathcal{D}}_{\text{det}} D ^ det and D ^ rand \hat{\mathcal{D}}_{\text{rand}} D ^ rand (Defined , Table 1) on these robust features only. We find features that satisfy both specifications by using the 10 linear features of a robust linear model trained on CIFAR-10. Training a linear model on the above robust features on D ^ rand \hat{\mathcal{D}}_{\text{rand}} D^rand and testing on the CIFAR test set incurs an accuracy of 23.5% (out of 88%).