Paper Accepted by ISSTA 2021

One paper entitled Attack as Defense: Characterizing Adversarial Examples using Robustness is accepted by ISSTA 2021.

This work proposes to use ensembled attack strategies to defense adversarial examples (potentially from adaptive attacks) based on the robustness difference between benign and adversarial examples.

Preprint and code coming soon.