%PDF-1.3 1 0 obj << /Kids [ 3 0 R 4 0 R 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R 10 0 R ] /Type /Pages /Count 8 >> endobj 2 0 obj << /Title (Adversarial Diversity and Hard Positive Generation) /Producer (PyPDF2) /Author (Andras Rozsa\054 Ethan M\056 Rudd\054 Terrance E\056 Boult) /Subject (2016 IEEE Conference on Computer Vision and Pattern Recognition Workshops) >> endobj 3 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 12 0 R /Resources << /XObject << /x8 13 0 R /x6 16 0 R /x12 19 0 R /x10 22 0 R >> /ExtGState << /s9 25 0 R /s11 28 0 R /a0 << /CA 1 /ca 1 >> /R21 31 0 R /s5 32 0 R /s7 35 0 R >> /Font << /F2 38 0 R /R28 39 0 R /F1 44 0 R /R38 45 0 R /R36 49 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R /R26 64 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] /ColorSpace << /R35 68 0 R /R33 70 0 R >> >> /MediaBox [ 0 0 612 792 ] /Annots [ 72 0 R 73 0 R 74 0 R 75 0 R 76 0 R 77 0 R 78 0 R 79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R ] >> endobj 4 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 85 0 R /Resources << /ColorSpace << /R35 68 0 R /R33 70 0 R >> /ExtGState << /R21 31 0 R >> /Font << /F2 86 0 R /R28 39 0 R /F1 87 0 R /R61 88 0 R /R63 92 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 96 0 R 97 0 R 98 0 R 99 0 R 100 0 R 101 0 R 102 0 R 103 0 R 104 0 R 105 0 R 106 0 R 107 0 R 108 0 R 109 0 R 110 0 R ] >> endobj 5 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 111 0 R /Resources << /ColorSpace << /R35 68 0 R /R33 70 0 R >> /ExtGState << /R21 31 0 R >> /Font << /F1 112 0 R /R24 56 0 R /F2 113 0 R /R28 39 0 R /R88 114 0 R /R61 88 0 R /R63 92 0 R /R90 117 0 R /R92 122 0 R /R22 53 0 R /R94 126 0 R /R86 130 0 R /R30 60 0 R /R84 133 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 137 0 R 138 0 R 139 0 R 140 0 R 141 0 R 142 0 R 143 0 R 144 0 R 145 0 R 146 0 R 147 0 R 148 0 R 149 0 R ] >> endobj 6 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 150 0 R /Resources << /ColorSpace << /R35 68 0 R /R33 70 0 R >> /ExtGState << /R21 31 0 R >> /Font << /R113 151 0 R /R117 154 0 R /R115 157 0 R /F2 160 0 R /R28 39 0 R /F1 161 0 R /R61 88 0 R /R63 92 0 R /R36 49 0 R /R92 122 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R /R84 133 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 162 0 R 163 0 R 164 0 R 165 0 R 166 0 R 167 0 R 168 0 R 169 0 R 170 0 R ] >> endobj 7 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 171 0 R /Resources << /XObject << /R130 172 0 R /R131 173 0 R /R132 174 0 R /R133 175 0 R /R134 176 0 R /R135 177 0 R /R136 178 0 R /R137 179 0 R /R138 180 0 R /R139 181 0 R /R129 182 0 R /R144 183 0 R /R141 184 0 R /R140 185 0 R /R143 186 0 R /R142 187 0 R >> /ExtGState << /R21 31 0 R >> /Font << /F2 188 0 R /F1 189 0 R /R90 117 0 R /R92 122 0 R /R86 130 0 R /R84 133 0 R /R145 190 0 R /R147 193 0 R /R113 151 0 R /R117 154 0 R /R115 157 0 R /R28 39 0 R /R61 88 0 R /R63 92 0 R /R36 49 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] /ColorSpace << /R35 68 0 R /R33 70 0 R >> >> /MediaBox [ 0 0 612 792 ] /Annots [ 196 0 R 197 0 R 198 0 R 199 0 R 200 0 R ] >> endobj 8 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 201 0 R /Resources << /ColorSpace << /R161 202 0 R /R528 204 0 R /R516 206 0 R /R35 68 0 R /R33 70 0 R /R511 207 0 R >> /XObject << /R335 209 0 R /R555 211 0 R /R372 213 0 R /R373 215 0 R /R370 216 0 R /R371 217 0 R /R376 218 0 R /R377 219 0 R /R374 220 0 R /R375 221 0 R /R378 222 0 R /R379 223 0 R /R541 224 0 R /R540 226 0 R /R279 228 0 R /R278 230 0 R /R545 231 0 R /R544 232 0 R /R547 233 0 R /R546 234 0 R /R549 235 0 R /R548 236 0 R /R271 237 0 R /R270 238 0 R /R277 239 0 R /R276 240 0 R /R275 241 0 R /R274 242 0 R /R178 243 0 R /R179 244 0 R /R428 245 0 R /R429 246 0 R /R174 247 0 R /R175 248 0 R /R176 249 0 R /R177 250 0 R /R170 251 0 R /R171 252 0 R /R172 253 0 R /R173 254 0 R /R181 255 0 R /R180 256 0 R /R183 257 0 R /R182 258 0 R /R185 259 0 R /R184 260 0 R /R187 261 0 R /R186 262 0 R /R189 263 0 R /R188 264 0 R /R533 265 0 R /R538 266 0 R /R539 267 0 R /R493 268 0 R /R492 270 0 R /R491 271 0 R /R490 272 0 R /R497 273 0 R /R496 274 0 R /R495 275 0 R /R494 276 0 R /R499 277 0 R /R498 278 0 R /R358 279 0 R /R359 280 0 R /R213 281 0 R /R212 282 0 R /R215 283 0 R /R214 284 0 R /R217 285 0 R /R216 286 0 R /R350 287 0 R /R351 288 0 R /R352 289 0 R /R353 290 0 R /R354 291 0 R /R355 292 0 R /R356 293 0 R /R357 294 0 R /R404 295 0 R /R405 296 0 R /R406 297 0 R /R407 298 0 R /R400 299 0 R /R401 301 0 R /R569 302 0 R /R568 304 0 R /R567 305 0 R /R566 306 0 R /R565 307 0 R /R564 308 0 R /R563 303 0 R /R562 309 0 R /R561 310 0 R /R560 311 0 R /R437 312 0 R /R436 313 0 R /R402 269 0 R /R403 314 0 R /R329 315 0 R /R328 316 0 R /R325 317 0 R /R324 318 0 R /R327 319 0 R /R326 320 0 R /R321 321 0 R /R320 322 0 R /R323 323 0 R /R322 324 0 R /R288 325 0 R /R289 326 0 R /R282 327 0 R /R283 328 0 R /R280 329 0 R /R281 330 0 R /R286 331 0 R /R287 332 0 R /R284 333 0 R /R285 334 0 R /R239 335 0 R /R238 336 0 R /R237 337 0 R /R236 338 0 R /R235 339 0 R /R234 340 0 R /R233 341 0 R /R232 342 0 R /R231 343 0 R /R230 344 0 R /R462 345 0 R /R463 347 0 R /R460 348 0 R /R461 349 0 R /R466 350 0 R /R467 351 0 R /R464 352 0 R /R465 353 0 R /R468 354 0 R /R469 355 0 R /R585 356 0 R /R584 357 0 R /R587 358 0 R /R586 359 0 R /R581 360 0 R /R580 361 0 R /R583 362 0 R /R582 363 0 R /R589 364 0 R /R588 365 0 R /R309 366 0 R /R308 368 0 R /R425 369 0 R /R272 229 0 R /R303 370 0 R /R302 371 0 R /R301 372 0 R /R300 373 0 R /R307 374 0 R /R306 375 0 R /R305 376 0 R /R304 377 0 R /R248 378 0 R /R450 379 0 R /R211 380 0 R /R448 381 0 R /R449 382 0 R /R440 383 0 R /R441 384 0 R /R442 385 0 R /R443 386 0 R /R444 387 0 R /R445 346 0 R /R446 388 0 R /R447 389 0 R /R398 390 0 R /R399 391 0 R /R394 392 0 R /R395 393 0 R /R210 394 0 R /R397 395 0 R /R390 396 0 R /R543 397 0 R /R392 398 0 R /R393 399 0 R /R542 400 0 R /R361 401 0 R /R360 402 0 R /R363 403 0 R /R362 404 0 R /R365 405 0 R /R364 406 0 R /R367 407 0 R /R366 408 0 R /R369 409 0 R /R368 410 0 R /R534 411 0 R /R273 412 0 R /R536 413 0 R /R537 414 0 R /R530 415 0 R /R531 416 0 R /R532 417 0 R /R249 418 0 R /R246 419 0 R /R247 420 0 R /R244 421 0 R /R245 422 0 R /R242 423 0 R /R243 424 0 R /R240 425 0 R /R241 426 0 R /R439 427 0 R /R438 428 0 R /R165 429 0 R /R164 212 0 R /R435 430 0 R /R434 431 0 R /R169 432 0 R /R168 433 0 R /R431 434 0 R /R430 435 0 R /R433 436 0 R /R432 437 0 R /R578 438 0 R /R579 439 0 R /R426 440 0 R /R427 441 0 R /R424 442 0 R /R264 443 0 R /R265 444 0 R /R266 445 0 R /R267 446 0 R /R260 447 0 R /R261 448 0 R /R349 449 0 R /R348 450 0 R /R347 451 0 R /R422 452 0 R /R345 453 0 R /R344 454 0 R /R343 455 0 R /R342 456 0 R /R341 457 0 R /R423 458 0 R /R552 459 0 R /R479 460 0 R /R550 461 0 R /R551 462 0 R /R556 463 0 R /R420 464 0 R /R554 465 0 R /R535 466 0 R /R558 467 0 R /R559 468 0 R /R419 469 0 R /R418 470 0 R /R413 471 0 R /R412 472 0 R /R411 473 0 R /R410 474 0 R /R417 475 0 R /R416 476 0 R /R415 477 0 R /R414 478 0 R /R219 479 0 R /R192 480 0 R /R193 481 0 R /R190 482 0 R /R191 483 0 R /R196 484 0 R /R197 485 0 R /R194 486 0 R /R195 487 0 R /R198 488 0 R /R199 489 0 R /R166 490 0 R /R408 491 0 R /R218 492 0 R /R299 493 0 R /R298 494 0 R /R291 495 0 R /R290 496 0 R /R293 497 0 R /R292 498 0 R /R295 499 0 R /R294 367 0 R /R297 500 0 R /R296 501 0 R /R409 502 0 R /R488 503 0 R /R489 504 0 R /R484 505 0 R /R485 506 0 R /R486 507 0 R /R487 508 0 R /R480 509 0 R /R481 510 0 R /R482 511 0 R /R483 512 0 R /R202 513 0 R /R203 514 0 R /R200 515 0 R /R201 516 0 R /R206 517 0 R /R207 225 0 R /R204 518 0 R /R205 519 0 R /R208 520 0 R /R209 521 0 R /R471 522 0 R /R470 523 0 R /R473 524 0 R /R472 525 0 R /R475 526 0 R /R474 527 0 R /R477 528 0 R /R476 529 0 R /R570 530 0 R /R478 531 0 R /R572 532 0 R /R573 533 0 R /R574 534 0 R /R575 535 0 R /R576 536 0 R /R577 537 0 R /R262 538 0 R /R263 539 0 R /R346 540 0 R /R167 541 0 R /R268 542 0 R /R269 543 0 R /R338 544 0 R /R339 545 0 R /R336 546 0 R /R337 214 0 R /R334 547 0 R /R340 548 0 R /R332 549 0 R /R333 550 0 R /R330 551 0 R /R331 552 0 R /R509 553 0 R /R508 554 0 R /R553 555 0 R /R505 556 0 R /R504 557 0 R /R507 558 0 R /R506 559 0 R /R501 560 0 R /R500 561 0 R /R503 562 0 R /R502 563 0 R /R396 564 0 R /R557 565 0 R /R228 566 0 R /R229 210 0 R /R220 567 0 R /R221 568 0 R /R222 569 0 R /R223 570 0 R /R571 571 0 R /R225 572 0 R /R226 573 0 R /R227 574 0 R /R459 575 0 R /R458 576 0 R /R457 577 0 R /R456 578 0 R /R455 579 0 R /R454 580 0 R /R453 581 0 R /R452 582 0 R /R451 583 0 R /R421 584 0 R /R383 585 0 R /R382 586 0 R /R381 587 0 R /R380 300 0 R /R387 588 0 R /R386 589 0 R /R385 590 0 R /R384 591 0 R /R389 592 0 R /R388 593 0 R /R596 594 0 R /R594 595 0 R /R595 596 0 R /R592 597 0 R /R593 598 0 R /R590 599 0 R /R591 600 0 R /R391 601 0 R /R314 602 0 R /R315 603 0 R /R316 604 0 R /R317 605 0 R /R310 606 0 R /R311 607 0 R /R312 608 0 R /R313 609 0 R /R318 610 0 R /R319 611 0 R /R259 612 0 R /R258 613 0 R /R255 614 0 R /R254 615 0 R /R257 616 0 R /R256 617 0 R /R251 618 0 R /R250 619 0 R /R253 620 0 R /R252 621 0 R /R529 227 0 R /R224 622 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] /Pattern << /R606 623 0 R /R603 626 0 R /R519 629 0 R /R522 632 0 R /R525 635 0 R /R609 638 0 R >> /ExtGState << /R162 641 0 R /R526 642 0 R /R159 643 0 R >> /Font << /R610 644 0 R /R599 647 0 R /R514 651 0 R /R512 655 0 R /R117 154 0 R /F2 659 0 R /R597 660 0 R /F1 664 0 R /R61 88 0 R /R36 49 0 R /R92 122 0 R /R22 53 0 R /R94 126 0 R /R24 56 0 R /R30 60 0 R /R84 133 0 R >> /Shading << /R605 624 0 R /R602 627 0 R /R518 630 0 R /R521 633 0 R /R608 639 0 R /R524 636 0 R >> >> /MediaBox [ 0 0 612 792 ] /Annots [ 665 0 R 666 0 R 667 0 R 668 0 R ] >> endobj 9 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 669 0 R /Resources << /ColorSpace << /R634 670 0 R /R511 207 0 R /R35 68 0 R /R33 70 0 R /R528 204 0 R >> /XObject << /R641 671 0 R /R646 673 0 R /R647 675 0 R /R660 676 0 R /R661 678 0 R /R662 679 0 R /R644 680 0 R /R645 674 0 R /R659 681 0 R /R658 682 0 R /R648 683 0 R /R649 684 0 R /R642 685 0 R /R643 686 0 R /R639 672 0 R /R652 687 0 R /R655 689 0 R /R654 690 0 R /R657 677 0 R /R656 691 0 R /R651 688 0 R /R653 692 0 R /R650 693 0 R /R640 694 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] /Pattern << /R638 695 0 R /R636 697 0 R >> /ExtGState << /R162 641 0 R /R159 643 0 R >> /Font << /R632 699 0 R /R610 644 0 R /F1 703 0 R /F2 704 0 R /R663 705 0 R /R665 709 0 R /R667 712 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R >> /Shading << /R637 696 0 R /R635 698 0 R >> >> /MediaBox [ 0 0 612 792 ] /Annots [ 716 0 R 717 0 R 718 0 R 719 0 R 720 0 R 721 0 R 722 0 R 723 0 R 724 0 R 725 0 R 726 0 R ] >> endobj 10 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 727 0 R /Resources << /ColorSpace << /R35 68 0 R /R33 70 0 R >> /ExtGState << /R21 31 0 R >> /Font << /R147 193 0 R /F2 728 0 R /F1 729 0 R /R22 53 0 R /R24 56 0 R /R30 60 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 730 0 R 731 0 R 732 0 R 733 0 R 734 0 R 735 0 R 736 0 R 737 0 R 738 0 R 739 0 R 740 0 R 741 0 R 742 0 R 743 0 R 744 0 R 745 0 R 746 0 R 747 0 R 748 0 R 749 0 R 750 0 R 751 0 R 752 0 R 753 0 R 754 0 R 755 0 R 756 0 R 757 0 R 758 0 R 759 0 R 760 0 R 761 0 R 762 0 R 763 0 R 764 0 R 765 0 R 766 0 R ] >> endobj 11 0 obj << /Type /Catalog /Pages 1 0 R >> endobj 12 0 obj << /Length 41602 >> stream q q q 0.10000 0 0 0.10000 0 0 cm /R21 gs 0 g q 10 0 0 10 0 0 cm BT /R22 14.34620 Tf 1 0 0 1 138.52100 675.06700 Tm [ (Adv) 10.00140 (ersarial) -250.01200 (Di) 10 (v) 9.99625 (ersity) -250.00300 (and) -249.99100 (Hard) -250 (P) 20.00610 (ositi) 10.00140 (v) 9.99625 (e) -250 (Generation) ] TJ /R24 11.95520 Tf 30.68090 -37.85820 Td [ (Andras) -249.98400 (Rozsa\054) -250 (Ethan) -250.01600 (M\056) -250.00800 (Rudd\054) -249.98700 (and) -249.98700 (T) 70.01640 (errance) -249.99500 (E\056) -250.01600 (Boult) ] TJ /R26 7.97010 Tf 256.81900 4.33906 Td (\041) Tj /R24 11.95520 Tf -232.93800 -18.28590 Td [ (Uni) 24.99570 (v) 14.98510 (ersity) -249.98900 (of) -250.01400 (Colorado) -249.98900 (at) -249.98700 (Colorado) -249.98900 (Springs) ] TJ -3.29375 -13.94800 Td [ (V) 59.99060 (ision) -250.01200 (and) -249.98700 (Security) -250.00600 (T) 70.01640 (echnology) -249.99700 (\050V) 134.99700 (AST\051) -249.98900 (Lab) ] TJ /R28 11.95520 Tf 18.80000 -13.94800 Td (\173) Tj /R24 11.95520 Tf 5.97695 0 Td (arozsa\054erudd\054tboult) Tj /R28 11.95520 Tf 91.63590 0 Td (\175) Tj /R24 11.95520 Tf 5.97695 0 Td [ (\100v) 25 (ast\056uccs\056edu) ] TJ /R22 11.95520 Tf -166.18400 -44.03520 Td (Abstract) Tj /R30 9.96260 Tf -83.92770 -15.23160 Td [ (State\055of\055the\055art) -291 (deep) -291.00900 (neur) 14.99010 (al) -290.99800 (networks) -291.01500 (suf) 18.01420 (fer) -291 (fr) 44.98510 (om) -291.98300 (a) -291.00500 (fun\055) ] TJ -11.95510 -11.95630 Td [ (damental) -313.01300 (pr) 44.98390 (oblem) -312.99100 (\320) -311.98200 (the) 30.00230 (y) -313.01200 (misclassify) -313 (adver) 10.00570 (sarial) -313.00900 (e) 19.99180 (xamples) ] TJ 11.95510 TL T* [ (formed) -351.01700 (by) -352.01900 (applying) -351.00400 (small) -351.01100 (perturbations) -351.99300 (to) -350.98800 (inputs\056) -614.01800 (In) -352.01700 (this) ] TJ T* [ (paper) 111.01800 (\054) -245.99600 (we) -243.98900 (pr) 36.98520 (esent) -245.00800 (a) -243.99400 (ne) 15.01830 (w) -245.00400 (psyc) 15.01960 (hometric) -244.01300 (per) 36.98160 (ceptual) -244.99800 (adver) 10.00570 (sar) 20.01380 (\055) ] TJ T* [ (ial) -318.98600 (similarity) -318.99300 (scor) 36.98650 (e) -319.01000 (\050P) 89.98620 (ASS\051) -318.99500 (measur) 36.99510 (e) -319.01000 (for) -318.98800 (quantifying) -318.99100 (adver) 20.00400 (\055) ] TJ T* [ (sarial) -240.00200 (ima) 10.01360 (g) 10.00320 (es\054) -243.01500 (intr) 44.99860 (oduce) -239.99300 (the) -239.99200 (notion) -240.98400 (of) -239.98700 (har) 36.99140 (d) -239.99400 (positive) -240.98900 (g) 10.00320 (ener) 15.01960 (a\055) ] TJ T* [ (tion\054) -208.01700 (and) -197.01100 (use) -198 (a) -196.98200 (diver) 10.00810 (se) -196.98600 (set) -197.01700 (of) -197.99400 (adver) 10.00570 (sarial) -196.98900 (perturbations) -196.99900 (\320) -198.00100 (not) ] TJ 11.95590 TL T* [ (just) -250.99100 (the) -251.00900 (closest) -252.01300 (ones) -251.00500 (\320) -251.01200 (for) -250.99900 (data) -252.01400 (augmentation\056) -312.98900 (W) 91.98710 (e) -252.00200 (intr) 44.99740 (oduce) ] TJ 11.95510 TL T* [ (a) -334.99800 (no) 10.00810 (vel) -335.00400 (hot\057cold) -335.98600 (appr) 44.99370 (oac) 14.98400 (h) -334.99800 (for) -334.98500 (adver) 10.00570 (sarial) -335.00500 (e) 19.99180 (xample) -336.01000 (g) 10.00320 (ener) 20 (\055) ] TJ T* [ (ation\054) -285.01900 (whic) 14.99870 (h) -277.98800 (pr) 44.98390 (o) 10.00320 (vides) -277.98300 (multiple) -277.99500 (possible) -277.99500 (adver) 10.00570 (sarial) -277.99500 (pertur) 19.98200 (\055) ] TJ T* [ (bations) -198.98500 (for) -197.98800 (e) 15.01280 (very) -198.99400 (single) -199 (ima) 10.01300 (g) 10.00320 (e) 15.01220 (\056) -291.98800 (The) -199.01100 (perturbations) -198.99900 (g) 10.00320 (ener) 15.01960 (ated) ] TJ T* [ (by) -442.98400 (our) -443.00800 (no) 10.00810 (vel) -442.98600 (appr) 44.99370 (oac) 14.98400 (h) -443.01900 (often) -443.00500 (corr) 36.98650 (espond) -443.00200 (to) -443.01200 (semantically) ] TJ T* [ (meaningful) -368.99100 (ima) 10.01300 (g) 10.00320 (e) -369.00200 (structur) 37.01220 (es\054) -398.98900 (and) -368.98300 (allow) -370.01900 (gr) 36.98650 (eater) -368.98700 (\337e) 19.99670 (xibility) ] TJ 11.95630 TL T* [ (to) -215.01100 (scale) -213.99400 (perturbation\055amplitudes\054) -222.01400 (whic) 14.99870 (h) -213.99900 (yields) -215.00600 (an) -215.01300 (incr) 36.98890 (eased) ] TJ 11.95470 TL T* [ (diver) 10.00810 (sity) -447.98800 (of) -447.99100 (adver) 10.00570 (sarial) -448.00600 (ima) 10.01300 (g) 10.00320 (es\056) -904.98300 (W) 91.98590 (e) -448.00900 (pr) 36.98650 (esent) -447.99400 (adver) 10.00570 (sarial) ] TJ T* [ (ima) 10.01360 (g) 10.00320 (es) -257.01400 (on) -257.98600 (se) 15.01890 (ver) 15.01470 (al) -257.00400 (network) -256.98800 (topolo) 9.99343 (gies) -257.00200 (and) -257.98100 (datasets\054) -259.01600 (includ\055) ] TJ T* [ (ing) -516.01400 (LeNet) -516.00500 (on) -517.00200 (the) -515.98500 (MNIST) -516 (dataset\054) -581.98700 (and) -516.99700 (Goo) 10.01060 (gLeN) 1.00964 (et) -517.00900 (and) ] TJ T* [ (ResidualNet) -318.99400 (on) -318.99600 (the) -318.01800 (Ima) 10.00320 (g) 10.00320 (eNet) -318.99300 (dataset\056) -517.01800 (F) 45.01700 (inally) 54.99820 (\054) -335.98100 (we) -318.99600 (demon\055) ] TJ 11.95590 TL T* [ (str) 14.99750 (ate) -481.01000 (on) -481.00800 (LeNet) -480.99200 (and) -481.00300 (Goo) 10.01060 (gLeNet) -480.98700 (that) -482.01300 (\336ne\055t) 0.99003 (uning) -482.01000 (with) -480.98600 (a) ] TJ 11.95510 TL T* [ (diver) 10.00810 (se) -190.98600 (set) -189.99800 (of) -191.01500 (har) 36.99020 (d) -190.98300 (positives) -190.01100 (impr) 44.99370 (o) 10.00320 (ves) -190.99000 (the) -190 (r) 45.01700 (ob) 20.00650 (ustness) -190.99500 (of) -191.01500 (these) ] TJ T* [ (networks) -311.99300 (compar) 36.99380 (ed) -311.98600 (to) -312.99400 (tr) 14.99140 (aining) -311.99200 (with) -311.99300 (prior) -311.99700 (methods) -312 (of) -312.99400 (g) 10.00320 (en\055) ] TJ T* [ (er) 15.01890 (ating) -250.00700 (adver) 10.00570 (sarial) -250 (ima) 10.01300 (g) 10.00320 (es\056) ] TJ /R22 14.34620 Tf 39.49570 TL T* [ (1) -999.98900 (Intr) 17.98820 (oduction) ] TJ /R24 9.96260 Tf 14.85310 TL T* [ (Deep) -289.99100 (neural) -291.00500 (netw) 10.00940 (orks) -290.01800 (are) -290.98300 (po) 24.98600 (werful) -289.98700 (learning) -290.01300 (models) -291.01800 (which) ] TJ 11.95510 TL T* [ (ha) 19.99730 (v) 14.98280 (e) -285.99600 (been) -285.99000 (successfully) -285.99900 (appli) 1 (ed) -285.99000 (to) -286.01800 (vision\054) -295.01200 (speech) -285.98900 (and) -285.98700 (man) 14.99010 (y) ] TJ T* [ (other) -419.01800 (tasks) -419.00800 (\133) ] TJ ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 102.17700 206.78100 Tm (9) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 107.15800 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 113.82300 206.78100 Tm (11) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 123.78600 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 130.45000 206.78100 Tm (18) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 140.41300 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 147.07800 206.78100 Tm (19) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 157.04100 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 163.70500 206.78100 Tm (10) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 173.66800 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 180.33300 206.78100 Tm (20) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 190.29600 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 196.96100 206.78100 Tm (4) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 201.94200 206.78100 Tm (\054) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 208.60700 206.78100 Tm (3) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 213.58800 206.78100 Tm [ (\135\056) -817 (Sze) 14.98280 (gedy) -419.01800 (et) -418.98600 (al\056) ] TJ -163.47600 -11.95470 Td (\133) Tj ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 53.42970 194.82600 Tm (21) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 63.39220 194.82600 Tm [ (\135) -297.01200 (sho) 24.99220 (wed) -295.98600 (that) -296.99500 (se) 25.01670 (v) 14.98280 (eral) -297.01400 (machine) -296.99300 (learning) -296.01200 (models\054) -309.01200 (includ\055) ] TJ -13.28010 -11.95510 Td [ (ing) -255 (state\055of\055the\055art) -255.98500 (deep) -255.01500 (neural) -255.99200 (netw) 10.00940 (orks\054) -255.98200 (misclassify) -255.99200 (small) ] TJ 11.95630 TL T* [ (non\055random) -242.98700 (perturbations) -242.98000 (of) -243.99700 (correctly) -243.01300 (classi\336ed) -242.98600 (images\056) -308.00300 (In) ] TJ 11.95470 TL T* [ (man) 14.99080 (y) -434.98100 (cases\054) -481.99600 (these) -435.01600 (misclassi\336cations) -434.98500 (are) -434.99800 (made) -435.01800 (with) -435.98400 (high) ] TJ T* [ (con\336dence\056) -292.99000 (Sze) 14.98400 (gedy) -201.01400 (et) -200.00300 (al\056) -293.98500 (\133) ] TJ ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 159.40200 147.00500 Tm (21) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 169.36400 147.00500 Tm [ (\135) -200.01000 (dubbed) -201.00400 (these) -199.99600 (perturbed) -201.01300 (mis\055) ] TJ -119.25200 -11.95510 Td [ (classi\336ed) -266.98100 (samples) ] TJ /R30 9.96260 Tf 74.49880 0 Td [ (adver) 10.00570 (sarial) -267.01700 (e) 19.99180 (xamples) ] TJ /R24 9.96260 Tf 85.36910 0 Td [ (\056) -360.99600 (In) -267.01200 (order) -267.01400 (to) -267.00200 (gener) 19.99420 (\055) ] TJ -159.86800 -11.95510 Td [ (alize) -315.00500 (well\054) -330.98800 (deep) -313.98600 (neural) -315.00100 (netw) 10.00940 (orks) -314.99400 (are) -315.01900 (e) 15.01220 (xpecte) 0.98513 (d) -315.00100 (to) -314.99400 (be) -315.00600 (rob) 20.00400 (ust) ] TJ 11.95510 TL T* [ (to) -300.01600 (moderate) -300.01600 (perturbations) -299.99000 (to) -300.01600 (their) -300.01600 (inputs\056) -460.00400 (Thus) -300.00900 (adv) 14.98280 (ersarial) ] TJ 11.95590 TL T* [ (e) 15.01280 (xamples\054) -250.00700 (with) -250.01500 (only) -250.01500 (small) -250.00900 (perturbations\054) -249.99700 (are) -250.01000 (problematic\056) ] TJ ET Q 3.98000 w 0 G 501.12100 904.14800 m 1446.11000 904.14800 l S q 10 0 0 10 0 0 cm BT /R36 5.97760 Tf 1 0 0 1 60.14100 83.81290 Tm (\041) Tj /R24 7.97010 Tf 4.31680 -2.81289 Td [ (This) -217.00500 (w) 10.01290 (ork) -216.98200 (supported) -217.01100 (in) -215.99900 (part) -217.00400 (by) -217 (NSF\0431320956) -216.98500 (RI\072) -216.99100 (Small\072) -292.99900 (Open) -216.97900 (V) 60.00520 (ision) ] TJ ET Q q 3147.69000 4296.35000 2244.59000 1346.48000 re W n /R33 cs 1 0.50195 0.50195 scn 3299.82000 4984.58000 m 3304.58000 4981.12000 3314.65000 4970.08000 3322.17000 4960.13000 c 3347.86000 4926.09000 3391.63000 4915.65000 3462.67000 4926.69000 c 3493.94000 4931.51000 3510.60000 4936.86000 3549.39000 4954.50000 c 3611.89000 4982.95000 3654.35000 4996.05000 3670.90000 4991.99000 c 3701.86000 4984.42000 3727.71000 4921.77000 3720.51000 4871.72000 c 3716.84000 4846.14000 3703.91000 4826.65000 3669.82000 4795.17000 c 3640.07000 4767.68000 3629.84000 4705.85000 3648.02000 4662.89000 c 3662.84000 4627.78000 3674.21000 4614.36000 3704.39000 4596.07000 c 3730.75000 4580.16000 3732.48000 4578.22000 3729.88000 4567.18000 c 3723.43000 4540.02000 3623.02000 4429.50000 3578.77000 4400.88000 c 3553.12000 4384.32000 3516.45000 4368.80000 3495.84000 4365.88000 c 3477.39000 4363.16000 3438.76000 4373.34000 3417.11000 4386.54000 c 3401.75000 4395.90000 3377.24000 4433.88000 3373.78000 4453.74000 c 3372.48000 4461.15000 3376.49000 4476.14000 3383.63000 4490.58000 c 3404.08000 4531.74000 3403.15000 4566.21000 3380.98000 4595.43000 c 3358.14000 4625.39000 3332.06000 4636.21000 3321.30000 4620.09000 c 3313.57000 4608.46000 3297.34000 4609.44000 3279.58000 4622.53000 c 3261.09000 4636.21000 3260.50000 4637.68000 3262.38000 4667.27000 c 3263.74000 4689.34000 3266.23000 4691.78000 3281.22000 4686.16000 c 3302.91000 4677.98000 3324.11000 4701.35000 3332.56000 4742.64000 c 3338.13000 4770.11000 3307.02000 4808.54000 3265.90000 4824.92000 c 3228.89000 4839.70000 3219.59000 4851.28000 3214.72000 4888.66000 c 3210.93000 4917.38000 3211.58000 4920.79000 3223.70000 4937.79000 c 3251.84000 4977.21000 3283.38000 4996.59000 3299.82000 4984.58000 c h f 6.64800 w 4 M 1 j /R33 CS 1 0 0 SCN 3299.82000 4984.58000 m 3304.58000 4981.12000 3314.65000 4970.08000 3322.17000 4960.13000 c 3347.86000 4926.09000 3391.63000 4915.65000 3462.67000 4926.69000 c 3493.94000 4931.51000 3510.60000 4936.86000 3549.39000 4954.50000 c 3611.89000 4982.95000 3654.35000 4996.05000 3670.90000 4991.99000 c 3701.86000 4984.42000 3727.71000 4921.77000 3720.51000 4871.72000 c 3716.84000 4846.14000 3703.91000 4826.65000 3669.82000 4795.17000 c 3640.07000 4767.68000 3629.84000 4705.85000 3648.02000 4662.89000 c 3662.84000 4627.78000 3674.21000 4614.36000 3704.39000 4596.07000 c 3730.75000 4580.16000 3732.48000 4578.22000 3729.88000 4567.18000 c 3723.43000 4540.02000 3623.02000 4429.50000 3578.77000 4400.88000 c 3553.12000 4384.32000 3516.45000 4368.80000 3495.84000 4365.88000 c 3477.39000 4363.16000 3438.76000 4373.34000 3417.11000 4386.54000 c 3401.75000 4395.90000 3377.24000 4433.88000 3373.78000 4453.74000 c 3372.48000 4461.15000 3376.49000 4476.14000 3383.63000 4490.58000 c 3404.08000 4531.74000 3403.15000 4566.21000 3380.98000 4595.43000 c 3358.14000 4625.39000 3332.06000 4636.21000 3321.30000 4620.09000 c 3313.57000 4608.46000 3297.34000 4609.44000 3279.58000 4622.53000 c 3261.09000 4636.21000 3260.50000 4637.68000 3262.38000 4667.27000 c 3263.74000 4689.34000 3266.23000 4691.78000 3281.22000 4686.16000 c 3302.91000 4677.98000 3324.11000 4701.35000 3332.56000 4742.64000 c 3338.13000 4770.11000 3307.02000 4808.54000 3265.90000 4824.92000 c 3228.89000 4839.70000 3219.59000 4851.28000 3214.72000 4888.66000 c 3210.93000 4917.38000 3211.58000 4920.79000 3223.70000 4937.79000 c 3251.84000 4977.21000 3283.38000 4996.59000 3299.82000 4984.58000 c h 3299.82000 4984.58000 m S 0 0.80078 1 scn 4463.50000 5365.78000 m 4431.20000 5306.38000 4431.96000 5238.48000 4465.71000 5158.08000 c 4497.21000 5083.26000 4500.77000 5033.60000 4475.61000 5021.80000 c 4444.71000 5007.30000 4398.51000 5030.68000 4359.02000 5080.77000 c 4312.54000 5139.63000 4249.63000 5180.21000 4215.11000 5173.55000 c 4200.51000 5170.80000 4196.12000 5166.90000 4191.47000 5152.61000 c 4173.24000 5096.61000 4163.56000 5087.64000 4131.15000 5096.57000 c 4101.39000 5104.79000 4069.96000 5124.87000 4037.28000 5156.57000 c 4000.12000 5192.71000 3989.45000 5197.36000 3943.15000 5197.73000 c 3905.38000 5198.07000 3867.46000 5206.18000 3853.67000 5216.89000 c 3846.74000 5222.30000 3846.57000 5226.73000 3852.74000 5242.80000 c 3861.56000 5265.53000 3858.15000 5287.93000 3843.93000 5300.96000 c 3829.69000 5314 3788.57000 5395.54000 3783.17000 5421.40000 c 3778.68000 5442.86000 l 3806.54000 5429.83000 l 3860.43000 5404.52000 3877.74000 5421.55000 3870.22000 5492.43000 c 3865.79000 5534.14000 3867.35000 5554.97000 3875.09000 5556.43000 c 3882.39000 5557.83000 3922.21000 5517.81000 3924.54000 5506.82000 c 3927.78000 5491.19000 3953.59000 5463.49000 3977.02000 5450.50000 c 4008.12000 5433.29000 4038.74000 5432.27000 4073.91000 5447.31000 c 4115.18000 5465.05000 4153.66000 5474.58000 4167.45000 5470.57000 c 4174.16000 5468.63000 4182.49000 5461.16000 4185.96000 5453.90000 c 4197.85000 5429.24000 4227.62000 5397.11000 4241.46000 5393.96000 c 4260.40000 5389.75000 4268.52000 5395.97000 4279.22000 5422.85000 c 4291.73000 5454.13000 4308 5468.46000 4336.09000 5472.79000 c 4382.07000 5479.82000 4466.42000 5434.32000 4473.94000 5398.41000 c 4475.02000 5393.05000 4470.37000 5378.38000 4463.50000 5365.78000 c h f 0 0 1 SCN 4463.50000 5365.78000 m 4431.20000 5306.38000 4431.96000 5238.48000 4465.71000 5158.08000 c 4497.21000 5083.26000 4500.77000 5033.60000 4475.61000 5021.80000 c 4444.71000 5007.30000 4398.51000 5030.68000 4359.02000 5080.77000 c 4312.54000 5139.63000 4249.63000 5180.21000 4215.11000 5173.55000 c 4200.51000 5170.80000 4196.12000 5166.90000 4191.47000 5152.61000 c 4173.24000 5096.61000 4163.56000 5087.64000 4131.15000 5096.57000 c 4101.39000 5104.79000 4069.96000 5124.87000 4037.28000 5156.57000 c 4000.12000 5192.71000 3989.45000 5197.36000 3943.15000 5197.73000 c 3905.38000 5198.07000 3867.46000 5206.18000 3853.67000 5216.89000 c 3846.74000 5222.30000 3846.57000 5226.73000 3852.74000 5242.80000 c 3861.56000 5265.53000 3858.15000 5287.93000 3843.93000 5300.96000 c 3829.69000 5314 3788.57000 5395.54000 3783.17000 5421.40000 c 3778.68000 5442.86000 l 3806.54000 5429.83000 l 3860.43000 5404.52000 3877.74000 5421.55000 3870.22000 5492.43000 c 3865.79000 5534.14000 3867.35000 5554.97000 3875.09000 5556.43000 c 3882.39000 5557.83000 3922.21000 5517.81000 3924.54000 5506.82000 c 3927.78000 5491.19000 3953.59000 5463.49000 3977.02000 5450.50000 c 4008.12000 5433.29000 4038.74000 5432.27000 4073.91000 5447.31000 c 4115.18000 5465.05000 4153.66000 5474.58000 4167.45000 5470.57000 c 4174.16000 5468.63000 4182.49000 5461.16000 4185.96000 5453.90000 c 4197.85000 5429.24000 4227.62000 5397.11000 4241.46000 5393.96000 c 4260.40000 5389.75000 4268.52000 5395.97000 4279.22000 5422.85000 c 4291.73000 5454.13000 4308 5468.46000 4336.09000 5472.79000 c 4382.07000 5479.82000 4466.42000 5434.32000 4473.94000 5398.41000 c 4475.02000 5393.05000 4470.37000 5378.38000 4463.50000 5365.78000 c h 4463.50000 5365.78000 m S 0 0.87109 0.52930 scn 4841.50000 4701.57000 m 4887 4787.43000 4901.39000 4798.95000 4949.98000 4788.19000 c 4966.10000 4784.62000 4990.39000 4783.11000 5003.91000 4784.84000 c 5029.28000 4788.02000 5031.07000 4789.21000 5076.90000 4833.26000 c 5096.86000 4852.41000 l 5103.63000 4841.15000 l 5115.90000 4820.65000 5125.86000 4815.29000 5146.80000 4817.94000 c 5169.68000 4820.86000 5191.87000 4833.91000 5209.93000 4855.06000 c 5225.79000 4873.67000 5232.39000 4869.02000 5241.37000 4832.98000 c 5247.53000 4808 5247.16000 4803.88000 5236.99000 4790.35000 c 5200.14000 4741.13000 5192.46000 4689.02000 5219.46000 4671.71000 c 5226.55000 4667.17000 5239.41000 4658.83000 5248.07000 4653.21000 c 5256.78000 4647.47000 5264.52000 4637.79000 5265.38000 4631.35000 c 5267.99000 4612.52000 5244.55000 4570.96000 5220.37000 4551.55000 c 5187.75000 4525.26000 5179.27000 4523.31000 5145.93000 4534.55000 c 5115.69000 4544.73000 5101.84000 4543.27000 5061.91000 4525.75000 c 5043.09000 4517.52000 4995.59000 4446.26000 4993.96000 4423.81000 c 4992.29000 4400.71000 4984.12000 4384.16000 4972.91000 4381.13000 c 4960.85000 4377.83000 4912.80000 4392.59000 4900.80000 4403.26000 c 4894.20000 4409.16000 4893.93000 4413.59000 4899.34000 4430.84000 c 4907.83000 4457.95000 4901.23000 4478.18000 4868.61000 4524.98000 c 4838.96000 4567.50000 4827.82000 4593.27000 4822.52000 4631.56000 c 4819.05000 4656.34000 4820.67000 4662.29000 4841.50000 4701.57000 c h f 0 0.50195 0 SCN 4841.50000 4701.57000 m 4887 4787.43000 4901.39000 4798.95000 4949.98000 4788.19000 c 4966.10000 4784.62000 4990.39000 4783.11000 5003.91000 4784.84000 c 5029.28000 4788.02000 5031.07000 4789.21000 5076.90000 4833.26000 c 5096.86000 4852.41000 l 5103.63000 4841.15000 l 5115.90000 4820.65000 5125.86000 4815.29000 5146.80000 4817.94000 c 5169.68000 4820.86000 5191.87000 4833.91000 5209.93000 4855.06000 c 5225.79000 4873.67000 5232.39000 4869.02000 5241.37000 4832.98000 c 5247.53000 4808 5247.16000 4803.88000 5236.99000 4790.35000 c 5200.14000 4741.13000 5192.46000 4689.02000 5219.46000 4671.71000 c 5226.55000 4667.17000 5239.41000 4658.83000 5248.07000 4653.21000 c 5256.78000 4647.47000 5264.52000 4637.79000 5265.38000 4631.35000 c 5267.99000 4612.52000 5244.55000 4570.96000 5220.37000 4551.55000 c 5187.75000 4525.26000 5179.27000 4523.31000 5145.93000 4534.55000 c 5115.69000 4544.73000 5101.84000 4543.27000 5061.91000 4525.75000 c 5043.09000 4517.52000 4995.59000 4446.26000 4993.96000 4423.81000 c 4992.29000 4400.71000 4984.12000 4384.16000 4972.91000 4381.13000 c 4960.85000 4377.83000 4912.80000 4392.59000 4900.80000 4403.26000 c 4894.20000 4409.16000 4893.93000 4413.59000 4899.34000 4430.84000 c 4907.83000 4457.95000 4901.23000 4478.18000 4868.61000 4524.98000 c 4838.96000 4567.50000 4827.82000 4593.27000 4822.52000 4631.56000 c 4819.05000 4656.34000 4820.67000 4662.29000 4841.50000 4701.57000 c h 4841.50000 4701.57000 m S [ 39.88800 39.88800 ] 0 d 1 J 1 0 0 SCN 3199.46000 5063.83000 m 3296.80000 5141.68000 3394.13000 5167.65000 v 3491.45000 5193.57000 3686.05000 5167.65000 y 3807.73000 5141.68000 3856.37000 5089.80000 v 3905.01000 5037.86000 3929.36000 4908.13000 y 3953.69000 4752.43000 3929.36000 4700.49000 v 3905.01000 4648.61000 3832.02000 4518.82000 3759.04000 4466.94000 c 3686.05000 4415.05000 3540.09000 4337.19000 3491.45000 4337.19000 c 3442.77000 4337.19000 3296.80000 4440.97000 3272.45000 4518.82000 c 3248.16000 4596.73000 3223.81000 4700.49000 3199.46000 4804.31000 c 3175.17000 4908.13000 3199.46000 5063.83000 y h 3199.46000 5063.83000 m S 0 0 0 scn q 10 0 0 10 0 0 cm BT /R38 7.75600 Tf 1 0 0 1 484.21500 553.43600 Tm [ (\041) 0.98210 (\042\043\044\043\045\046\047\050) 1.01358 (\051) 0.99469 (\052\046\044\053) ] TJ 9.69492 TL T* [ (\054\055\056) 3.97877 (\057) 0.98840 (0) 0.98210 (1) ] TJ -0.00776 Tc (\05701) ' 0 Tc T* [ (\057) 0.98840 (0) 0.98210 (2) 0.98210 (\050) 0.99469 (345) 1.00728 (6) ] TJ T* [ (789) 1.00728 (\072) 0.99469 (\0738\047\074\050) 0.98210 (345) 1.00728 (\075) ] TJ ET Q [ 0.69250 0.69250 ] 0 d 2.21600 w 0 j 0 0 0 SCN 3148.77000 4297.44000 2242.40000 1344.31000 re S [ 39.88800 39.88800 ] 0 d 6.64800 w 1 j 0 0.50195 0 SCN 4655.50000 4700.32000 m 4655.50000 4895.30000 4782.27000 4960.29000 v 4909.08000 5025.32000 5162.59000 4960.29000 y 5352.76000 4830.34000 5352.76000 4765.31000 v 5352.76000 4700.32000 5289.36000 4570.32000 y 5099.18000 4375.34000 5035.83000 4375.34000 v 4972.43000 4375.34000 4909.08000 4310.31000 4845.67000 4375.34000 c 4782.27000 4440.32000 4718.90000 4570.32000 y 4655.50000 4635.30000 4655.50000 4700.32000 v h 4655.50000 4700.32000 m S 0 j 0 0 1 SCN 3715.97000 5478.79000 m 3715.97000 5360.47000 3777.38000 5242.09000 v 3838.83000 5123.77000 4023.11000 4946.27000 y 4084.57000 4887.09000 4207.44000 4887.09000 v 4330.30000 4887.09000 4514.62000 4946.27000 y 4576.08000 5005.41000 4576.08000 5064.59000 v 4576.08000 5123.77000 4514.62000 5360.47000 y 4514.62000 5419.67000 4391.75000 5478.79000 v 4268.89000 5537.99000 3900.24000 5597.17000 y 3715.97000 5537.99000 3715.97000 5478.79000 v h 3715.97000 5478.79000 m S 4816.67000 5555.68000 m 4816.67000 5542.14000 4805.95000 5531.21000 4792.81000 5531.16000 c 4779.61000 5531.16000 4768.96000 5542.09000 4768.90000 5555.62000 c 4768.85000 5569.15000 4779.50000 5580.12000 4792.70000 5580.18000 c 4805.86000 5580.23000 4816.62000 5569.30000 4816.67000 5555.79000 c f 0 0 1 scn 4114.55000 5241.67000 m 4114.55000 5230.31000 4105.55000 5221.11000 4094.46000 5221.11000 c 4083.43000 5221.11000 4074.45000 5230.25000 4074.39000 5241.61000 c 4074.39000 5252.97000 4083.33000 5262.22000 4094.41000 5262.22000 c 4105.45000 5262.28000 4114.49000 5253.14000 4114.55000 5241.78000 c f 1 0 0 scn 3584.93000 4843.70000 m 3584.93000 4832.39000 3575.96000 4823.14000 3564.87000 4823.14000 c 3553.83000 4823.14000 3544.85000 4832.33000 3544.80000 4843.65000 c 3544.80000 4855 3553.72000 4864.25000 3564.81000 4864.31000 c 3575.85000 4864.31000 3584.88000 4855.17000 3584.93000 4843.80000 c f 0.50195 0.50195 0 scn 4977.84000 4721.70000 m 4977.84000 4710.34000 4968.86000 4701.14000 4957.82000 4701.09000 c 4946.74000 4701.09000 4937.75000 4710.29000 4937.69000 4721.64000 c 4937.69000 4733 4946.63000 4742.20000 4957.72000 4742.25000 c 4968.74000 4742.30000 4977.79000 4733.11000 4977.84000 4721.75000 c f 0 0 0 scn 4763.27000 5441.30000 m 4791.67000 5484.58000 l 4820.02000 5441.30000 l h f* [ ] 0 d 7.75600 w 0 J 0.50195 0.50195 0.50195 SCN 4763.27000 5441.30000 m 4791.67000 5484.58000 l 4820.02000 5441.30000 l h 4763.27000 5441.30000 m S 4771.49000 5347.12000 39.05860 39.10940 re f 1 J 1 j 4771.49000 5347.12000 39.05860 39.10940 re S 4819.59000 5279.16000 m 4808.94000 5246.21000 l 4774.36000 5246.16000 l 4763.60000 5279.05000 l 4791.52000 5299.45000 l h f* 7.75601 w 4819.59000 5279.16000 m 4808.94000 5246.21000 l 4774.36000 5246.16000 l 4763.60000 5279.05000 l 4791.52000 5299.45000 l h 4819.59000 5279.16000 m S 4810.72000 5152.29000 m 4792.97000 5161.81000 l 4775.01000 5152.61000 l 4778.64000 5172.47000 l 4764.30000 5186.64000 l 4784.31000 5189.36000 l 4793.41000 5207.37000 l 4802.11000 5189.18000 l 4822.08000 5186.11000 l 4807.46000 5172.15000 l h f* 7.75600 w 4810.72000 5152.29000 m 4792.97000 5161.81000 l 4775.01000 5152.61000 l 4778.64000 5172.47000 l 4764.30000 5186.64000 l 4784.31000 5189.36000 l 4793.41000 5207.37000 l 4802.11000 5189.18000 l 4822.08000 5186.11000 l 4807.46000 5172.15000 l h 4810.72000 5152.29000 m S 0 0 1 scn 4194.28000 5124.91000 m 4219.82000 5163.87000 l 4245.36000 5124.91000 l h f* 7.75600 w 0 J 0 j 0 0.50195 0 SCN 4194.28000 5124.91000 m 4219.82000 5163.87000 l 4245.36000 5124.91000 l h 4194.28000 5124.91000 m S 4273 5071.73000 m 4257.05000 5080.34000 l 4240.92000 5072 l 4244.11000 5089.87000 l 4231.29000 5102.68000 l 4249.25000 5105.12000 l 4257.42000 5121.30000 l 4265.32000 5104.95000 l 4283.23000 5102.20000 l 4270.14000 5089.64000 l h f* 7.75600 w 1 J 1 j 4273 5071.73000 m 4257.05000 5080.34000 l 4240.92000 5072 l 4244.11000 5089.87000 l 4231.29000 5102.68000 l 4249.25000 5105.12000 l 4257.42000 5121.30000 l 4265.32000 5104.95000 l 4283.23000 5102.20000 l 4270.14000 5089.64000 l h 4273 5071.73000 m S 4433.19000 4942.59000 m 4420.27000 4949.57000 l 4407.18000 4942.87000 l 4409.78000 4957.32000 l 4399.38000 4967.64000 l 4413.93000 4969.65000 l 4420.54000 4982.74000 l 4426.92000 4969.54000 l 4441.47000 4967.27000 l 4430.82000 4957.09000 l h f* 5.54000 w 4433.19000 4942.59000 m 4420.27000 4949.57000 l 4407.18000 4942.87000 l 4409.78000 4957.32000 l 4399.38000 4967.64000 l 4413.93000 4969.65000 l 4420.54000 4982.74000 l 4426.92000 4969.54000 l 4441.47000 4967.27000 l 4430.82000 4957.09000 l h 4433.19000 4942.59000 m S 4012.45000 5128.38000 m 3996.49000 5136.98000 l 3980.32000 5128.70000 l 3983.56000 5146.56000 l 3970.69000 5159.32000 l 3988.70000 5161.76000 l 3996.88000 5177.93000 l 4004.71000 5161.60000 l 4022.67000 5158.84000 l 4009.52000 5146.29000 l h f* 7.75600 w 1 0 0 SCN 4012.45000 5128.38000 m 3996.49000 5136.98000 l 3980.32000 5128.70000 l 3983.56000 5146.56000 l 3970.69000 5159.32000 l 3988.70000 5161.76000 l 3996.88000 5177.93000 l 4004.71000 5161.60000 l 4022.67000 5158.84000 l 4009.52000 5146.29000 l h 4012.45000 5128.38000 m S 3946.66000 5073.47000 m 3933.73000 5080.44000 l 3920.64000 5073.74000 l 3923.29000 5088.18000 l 3912.84000 5098.51000 l 3927.39000 5100.52000 l 3934.05000 5113.61000 l 3940.44000 5100.41000 l 3954.94000 5098.14000 l 3944.34000 5087.97000 l h f* 5.54000 w 3946.66000 5073.47000 m 3933.73000 5080.44000 l 3920.64000 5073.74000 l 3923.29000 5088.18000 l 3912.84000 5098.51000 l 3927.39000 5100.52000 l 3934.05000 5113.61000 l 3940.44000 5100.41000 l 3954.94000 5098.14000 l 3944.34000 5087.97000 l h 3946.66000 5073.47000 m S 4009.09000 5102.74000 m 4034.63000 5141.68000 l 4060.17000 5102.74000 l h f* 7.75600 w 0 J 0 j 4009.09000 5102.74000 m 4034.63000 5141.68000 l 4060.17000 5102.74000 l h 4009.09000 5102.74000 m S 3866.48000 5125.36000 35.22270 35.16410 re f 1 J 1 j 3866.48000 5125.36000 35.22270 35.16410 re S 3960.30000 5171.71000 m 3950.73000 5142.07000 l 3919.55000 5142.02000 l 3909.88000 5171.60000 l 3935.03000 5190 l h f* 7.75601 w 3960.30000 5171.71000 m 3950.73000 5142.07000 l 3919.55000 5142.02000 l 3909.88000 5171.60000 l 3935.03000 5190 l h 3960.30000 5171.71000 m S 0 0.50195 0 scn 4820.99000 4887.89000 35.16410 35.16800 re f 7.75600 w 0 0 1 SCN 4820.99000 4887.89000 35.16410 35.16800 re S 4902.96000 4864.80000 m 4893.38000 4835.16000 l 4862.22000 4835.09000 l 4852.53000 4864.69000 l 4877.70000 4883.03000 l h f* 7.75601 w 4902.96000 4864.80000 m 4893.38000 4835.16000 l 4862.22000 4835.09000 l 4852.53000 4864.69000 l 4877.70000 4883.03000 l h 4902.96000 4864.80000 m S 4892.85000 4801.50000 m 4918.39000 4840.45000 l 4943.91000 4801.50000 l h f* 7.75600 w 0 J 0 j 4892.85000 4801.50000 m 4918.39000 4840.45000 l 4943.91000 4801.50000 l h 4892.85000 4801.50000 m S 4871.96000 4773.32000 m 4855.95000 4781.91000 l 4839.82000 4773.64000 l 4843.07000 4791.49000 l 4830.20000 4804.25000 l 4848.16000 4806.69000 l 4856.38000 4822.87000 l 4864.22000 4806.54000 l 4882.19000 4803.77000 l 4869.04000 4791.23000 l h f* 7.75600 w 1 J 1 j 4871.96000 4773.32000 m 4855.95000 4781.91000 l 4839.82000 4773.64000 l 4843.07000 4791.49000 l 4830.20000 4804.25000 l 4848.16000 4806.69000 l 4856.38000 4822.87000 l 4864.22000 4806.54000 l 4882.19000 4803.77000 l 4869.04000 4791.23000 l h 4871.96000 4773.32000 m S 4757.05000 4869.34000 m 4744.12000 4876.26000 l 4731.03000 4869.56000 l 4733.68000 4884 l 4723.24000 4894.38000 l 4737.79000 4896.34000 l 4744.45000 4909.49000 l 4750.82000 4896.22000 l 4765.32000 4893.96000 l 4754.72000 4883.85000 l h f* 5.54000 w 4757.05000 4869.34000 m 4744.12000 4876.26000 l 4731.03000 4869.56000 l 4733.68000 4884 l 4723.24000 4894.38000 l 4737.79000 4896.34000 l 4744.45000 4909.49000 l 4750.82000 4896.22000 l 4765.32000 4893.96000 l 4754.72000 4883.85000 l h 4757.05000 4869.34000 m S 4797.35000 4743.44000 m 4822.89000 4782.40000 l 4848.43000 4743.44000 l h f* 7.75600 w 0 J 0 j 1 0 0 SCN 4797.35000 4743.44000 m 4822.89000 4782.40000 l 4848.43000 4743.44000 l h 4797.35000 4743.44000 m S 4820.79000 4682.59000 m 4804.76000 4691.14000 l 4788.64000 4682.86000 l 4791.89000 4700.71000 l 4779.01000 4713.47000 l 4796.98000 4715.96000 l 4805.20000 4732.14000 l 4813.04000 4715.81000 l 4831.01000 4712.98000 l 4817.86000 4700.48000 l h f* 7.75600 w 1 J 1 j 4820.79000 4682.59000 m 4804.76000 4691.14000 l 4788.64000 4682.86000 l 4791.89000 4700.71000 l 4779.01000 4713.47000 l 4796.98000 4715.96000 l 4805.20000 4732.14000 l 4813.04000 4715.81000 l 4831.01000 4712.98000 l 4817.86000 4700.48000 l h 4820.79000 4682.59000 m S 4701.17000 4676.69000 m 4688.23000 4683.67000 l 4675.14000 4676.95000 l 4677.80000 4691.41000 l 4667.35000 4701.79000 l 4681.91000 4703.73000 l 4688.56000 4716.88000 l 4694.94000 4703.63000 l 4709.44000 4701.36000 l 4698.83000 4691.24000 l h f* 5.54000 w 4701.17000 4676.69000 m 4688.23000 4683.67000 l 4675.14000 4676.95000 l 4677.80000 4691.41000 l 4667.35000 4701.79000 l 4681.91000 4703.73000 l 4688.56000 4716.88000 l 4694.94000 4703.63000 l 4709.44000 4701.36000 l 4698.83000 4691.24000 l h 4701.17000 4676.69000 m S 1 0 0 scn 3762.23000 4807.51000 m 3746.21000 4816.11000 l 3730.10000 4807.77000 l 3733.35000 4825.63000 l 3720.46000 4838.45000 l 3738.42000 4840.88000 l 3746.65000 4857.05000 l 3754.50000 4840.72000 l 3772.40000 4837.91000 l 3759.30000 4825.42000 l h f* 7.75600 w 0 0.50195 0 SCN 3762.23000 4807.51000 m 3746.21000 4816.11000 l 3730.10000 4807.77000 l 3733.35000 4825.63000 l 3720.46000 4838.45000 l 3738.42000 4840.88000 l 3746.65000 4857.05000 l 3754.50000 4840.72000 l 3772.40000 4837.91000 l 3759.30000 4825.42000 l h 3762.23000 4807.51000 m S 3916.37000 4801.98000 m 3903.44000 4808.96000 l 3890.39000 4802.25000 l 3892.99000 4816.70000 l 3882.55000 4827.09000 l 3897.16000 4829.03000 l 3903.77000 4842.13000 l 3910.14000 4828.92000 l 3924.65000 4826.66000 l 3914.04000 4816.49000 l h f* 5.54000 w 3916.37000 4801.98000 m 3903.44000 4808.96000 l 3890.39000 4802.25000 l 3892.99000 4816.70000 l 3882.55000 4827.09000 l 3897.16000 4829.03000 l 3903.77000 4842.13000 l 3910.14000 4828.92000 l 3924.65000 4826.66000 l 3914.04000 4816.49000 l h 3916.37000 4801.98000 m S 3673.13000 4760.43000 m 3698.66000 4799.39000 l 3724.20000 4760.43000 l h f* 7.75600 w 0 J 0 j 3673.13000 4760.43000 m 3698.66000 4799.39000 l 3724.20000 4760.43000 l h 3673.13000 4760.43000 m S 3738.32000 4971 m 3722.36000 4979.61000 l 3706.19000 4971.32000 l 3709.43000 4989.17000 l 3696.55000 5001.95000 l 3714.57000 5004.38000 l 3722.73000 5020.56000 l 3730.58000 5004.21000 l 3748.54000 5001.46000 l 3735.39000 4988.91000 l h f* 7.75600 w 1 J 1 j 0 0 1 SCN 3738.32000 4971 m 3722.36000 4979.61000 l 3706.19000 4971.32000 l 3709.43000 4989.17000 l 3696.55000 5001.95000 l 3714.57000 5004.38000 l 3722.73000 5020.56000 l 3730.58000 5004.21000 l 3748.54000 5001.46000 l 3735.39000 4988.91000 l h 3738.32000 4971 m S 3829.10000 5066 m 3816.11000 5072.93000 l 3803.07000 5066.22000 l 3805.67000 5080.72000 l 3795.29000 5091.04000 l 3809.84000 5093.05000 l 3816.44000 5106.14000 l 3822.83000 5092.89000 l 3837.38000 5090.67000 l 3826.71000 5080.50000 l h f* 5.54000 w 3829.10000 5066 m 3816.11000 5072.93000 l 3803.07000 5066.22000 l 3805.67000 5080.72000 l 3795.29000 5091.04000 l 3809.84000 5093.05000 l 3816.44000 5106.14000 l 3822.83000 5092.89000 l 3837.38000 5090.67000 l 3826.71000 5080.50000 l h 3829.10000 5066 m S 3696.99000 5035.10000 m 3687.40000 5005.46000 l 3656.25000 5005.41000 l 3646.57000 5034.99000 l 3671.72000 5053.39000 l h f* 7.75601 w 3696.99000 5035.10000 m 3687.40000 5005.46000 l 3656.25000 5005.41000 l 3646.57000 5034.99000 l 3671.72000 5053.39000 l h 3696.99000 5035.10000 m S 3670.36000 5074.50000 35.21880 35.22270 re f 7.75600 w 3670.36000 5074.50000 35.21880 35.22270 re S 3572.82000 4999.35000 m 3598.36000 5038.30000 l 3623.89000 4999.35000 l h f* 0 J 0 j 3572.82000 4999.35000 m 3598.36000 5038.30000 l 3623.89000 4999.35000 l h 3572.82000 4999.35000 m S Q 0 g q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 308.86200 416.28600 Tm [ (Figure) -367.99300 (1\072) -572.01000 (A) ] TJ 0.17534 Tc /R24 7.97010 Tf 50.81600 0 Td [ (DV) -39.97790 (E) -38.99460 (R) -39.99320 (S) -39.00380 (A) -39.98400 (R) -39.99320 (I) -39.98100 (A) -39.00380 (L) -40.02390 (S) -500.00100 (A) -39.00690 (N) -39.98710 (D) ] TJ 0 Tc /R24 9.96260 Tf 86.07070 0 Td (H) Tj 0.49415 Tc /R24 7.97010 Tf 7.69102 0 Td (ARD) Tj 0 Tc /R24 9.96260 Tf 21.97030 0 Td (P) Tj 0.49415 Tc /R24 7.97010 Tf 6.03672 0 Td [ (OS) 1.01086 (ITIV) 1.01086 (ES) ] TJ 0 Tc /R24 9.96260 Tf 39.10310 0 Td (\056) Tj /R30 8.96640 Tf 9.11289 0 Td (This) Tj -220.80100 -10.95900 Td [ (paper) -458.02000 (demonstr) 15.01920 (ates) -458.00900 (how) -456.98800 (to) -457.99200 (g) 10.02000 (ener) 14.99740 (ate) -458.01400 (a) -458.00300 (muc) 15.00280 (h) -458.00300 (mor) 36.98160 (e) -457.97600 (diver) 9.99826 (se) -457.01800 (set) ] TJ 10.95900 TL T* [ (of) -414.99600 (adver) 9.98737 (sarial) -414.01900 (e) 20.02100 (xamples) -414.99600 (than) -414.99900 (the) -415.01500 (e) 20.02380 (xisting) -413.99100 (L\055BFGS) -415.02100 (\133) ] TJ ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R30 8.96640 Tf 1 0 0 1 504.29400 394.36800 Tm (21) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R30 8.96640 Tf 1 0 0 1 513.26000 394.36800 Tm [ (\135) -414.99900 (or) -413.99700 (fast) ] TJ -204.39800 -10.95900 Td [ (gr) 14.98920 (adient) -402.98300 (sign) -403.01000 (\050FGS\051) -402.02200 (\133) ] TJ ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R30 8.96640 Tf 1 0 0 1 390.78800 383.40900 Tm (8) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R30 8.96640 Tf 1 0 0 1 395.27100 383.40900 Tm [ (\135) -403.01800 (methods\056) -768.00900 (V) 74.01220 (ia) -403.01300 (a) -402.98000 (r) 14.99200 (ang) 10.02000 (e) -402.99600 (of) -402.01100 (perturbation) ] TJ -86.40900 -10.95900 Td [ (amplitudes) -339.98200 (along) -340.02000 (the) -339.99500 (learnt) -340.98100 (adver) 9.98737 (sarial) -340 (dir) 36.99790 (ections) -340 (\320) -339.98500 (not) -340.01700 (just) -340.00600 (the) ] TJ 10.95900 TL T* [ (closest) -393.01500 (adver) 9.98737 (sarial) -392.01800 (sample) -393.02000 (\320) -392.00200 (we) -393.00900 (can) -392.98200 (g) 10.02000 (ener) 14.99740 (ate) -392.01300 (har) 36.99250 (d) -393.00400 (positives) -392.00200 (to) ] TJ T* [ (\336ne\055tune) -310.01200 (the) -310.02200 (class) -311.01400 (de\336nitions\054) -325.00900 (ther) 36.98160 (eby) -310.00600 (e) 20.02380 (xtending) -309.99000 (pr) 36.99250 (e) 15.01370 (viously) -309.98400 (o) 10.02000 (ver) 20.00740 (\055) ] TJ T* [ (\336t) -293.01300 (decision) -293.99600 (boundaries) -292.98000 (to) -293.01300 (impr) 45.00850 (o) 10.02000 (ve) -294.01800 (both) -293.01600 (accur) 14.99740 (acy) -293.01600 (and) -292.97700 (r) 45.00850 (ob) 19.99650 (ustness\056) ] TJ T* [ (The) -203.01500 (e) 20.02100 (xtended) -203.02000 (decision) -201.98600 (boundaries) -203.02000 (ar) 36.99250 (e) -202.98800 (r) 36.99250 (epr) 37.01430 (esented) -203.01500 (by) -202.99300 (dashed) -201.98600 (lines\056) ] TJ T* [ (This) -324.01000 (simpli\336ed) -324.99500 (sc) 15.01650 (hematic) -323.98200 (uses) -325.00900 (shape) 0.98567 (s) -324.99300 (to) -323.98500 (depict) -325.02000 (dif) 18.00890 (fer) 36.98160 (ent) -324.00700 (types) -324.01800 (of) ] TJ 10.95820 TL T* [ (har) 36.98980 (d) -407.99000 (positive) -407.99600 (e) 20.02100 (xamples\056) -784.01700 (Inner) -408.01700 (color) 10.01460 (s) -407.98500 (depict) -408.01200 (the) -408.00100 (original) -407 (class\054) ] TJ 10.95900 TL T* [ (while) -351.99500 (outer) -351.01200 (color) 10.01460 (s) -352.00300 (depict) -351.98400 (the) -352.02000 (classi\336cation) -351.00100 (by) -351.98700 (the) -352.02000 (base) -351.02300 (network\056) ] TJ T* [ (F) 104.98700 (or) -251.02100 (better) -250.99700 (visualization) -250.99100 (we) -250.98600 (show) -251.00800 (only) -250.99100 (one) -251.00200 (input) -251.00800 (ima) 10.02000 (g) 10.02000 (e) -250.99700 (with) -250.99100 (corr) 37.01970 (e\055) ] TJ T* [ (sponding) -250.01100 (adver) 9.98737 (sarial\057har) 36.98160 (d) -249.97800 (positive) -249.98400 (e) 20.02380 (xamples) -250.01100 (for) -250.01100 (eac) 14.99200 (h) -249.97800 (class\056) ] TJ /R24 9.96260 Tf 11.95510 -24.35000 Td [ (A) -592.01600 (deeper) -591.98700 (problem) -593.01100 (is) -592.00400 (that) -592.00400 (the) -592.00900 (generated) -593 (adv) 14.98280 (ersarial) ] TJ -11.95510 -11.95510 Td [ (images) -381.99300 (are) -381.98800 (relati) 24.98600 (v) 14.98280 (ely) -382.00700 (portable) -381.99500 (across) -382.01000 (dif) 24.98600 (ferent) -383 (neural) -382.01000 (net\055) ] TJ 11.95470 TL T* [ (w) 10 (orks\054) -239.00400 (which) -237.00500 (means) -235.98500 (that) -235.98500 (the) 14.98770 (y) -237.01400 (are) -236.01000 (consistently) -237.00500 (misclassi\336ed) ] TJ 11.95630 TL T* [ (by) -247.00800 (models) -246.98600 (of) -247.01500 (similar) -246.98600 (netw) 10.00810 (ork) -247.01300 (architectures) -247.00800 (trained) -247.00300 (on) -247.00800 (v) 24.98110 (ary\055) ] TJ 11.95510 TL T* [ (ing) -366 (training) -367.00700 (data\054) -394.98800 (with) -367.01500 (dif) 24.98600 (ferent) -365.98300 (h) 4.98446 (yperparameters\054) -394.98300 (or) -366.99800 (e) 25.01050 (v) 14.98280 (en) ] TJ T* [ (dif) 24.98600 (ferent) -456.98500 (numbers) -456.99700 (of) -456.98000 (l) 0.98758 (ayers) -456.98300 (or) -456.98300 (types) -457.00200 (of) -456.98300 (acti) 24.98110 (v) 24.98110 (ations) -456.99700 (\133) ] TJ ET Q /R33 cs 0 1 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 529.34400 189.69400 Tm (21) Tj ET Q /R35 cs 0 scn q 10 0 0 10 0 0 cm BT /R24 9.96260 Tf 1 0 0 1 539.30700 189.69400 Tm (\135\056) Tj -230.44500 -11.95510 Td [ (While) -409.01500 (one) -408.98600 (classi\336cation) -410 (error) -409 (is) -409.01500 (a) -408.99500 (simple) -408.99500 (practical) -410.00500 (prob\055) ] TJ 11.95510 TL T* [ (lem\054) -375.99900 (these) -350.99000 (highly) -351.00500 (une) 14.98280 (xpected) -352.01000 (recognit) 1 (ion) -352 (errors) -351.00500 (suggest) -351.01000 (a) ] TJ T* [ (more) -336.99300 (fundamental) -337.99300 (problem\056) -571.99300 (Namely) 64.98920 (\054) -360.01300 (the) -336.99300 (combinations) -338.00700 (of) ] TJ 11.95590 TL T* [ (training) -216.01300 (samples) -216.01500 (and) -215.99800 (algorithms) -215.99300 (that) -215.98800 (we) -216.00300 (use) -215.99800 (to) -217.01300 (train) -215.99300 (our) -215.99800 (net\055) ] TJ 11.95510 TL T* [ (w) 10 (orks) -249.98500 (are) -250.01000 (not) -250.02000 (suf) 24.98360 (\336cient\056) ] TJ 11.95510 -13.05200 Td [ (At) -455.99300 (their) -455.99000 (core\054) -507.99900 (adv) 14.98280 (ersarial) -456.00200 (e) 15.01220 (xamples) -456.01700 (are) -456.01200 (nothing) -456.00200 (more) ] TJ -11.95510 -11.95590 Td [ (than) -447.99100 (perturbed) -447.99100 (v) 14.98280 (ersions) -449.00100 (of) -448.00400 (ordinary) -447.98900 (e) 15.01220 (xamples) -448.01800 (that) -449.00800 (cause) ] TJ T* [ (une) 14.98280 (xpected) -197.01600 (recognition) -198.01100 (mist) 1.01454 (ak) 9.99833 (es) -198.00600 (in) -197.01600 (netw) 10.00810 (orks\056) -292.01500 (This) -197.98200 (suggests) ] TJ T* [ (that) -397.01700 (the) -396.98500 (adv) 14.98280 (ersarial) -398.01200 (problem) -397.00700 (can) -396.99700 (be) -396.99300 (addressed) -396.98300 (by) -398.00200 (\336nding) ] TJ ET Q Q Q q q 1 1 1 rg /a0 gs 48.40600 786.42200 515.18800 -52.69900 re f q /s5 gs /x6 Do Q q /s7 gs /x8 Do Q q /s9 gs /x10 Do Q q /s11 gs /x12 Do Q Q Q Q q 1 0 0 1 0 0 cm BT /F1 12 Tf 14.40000 TL ET 1 1 1 rg n 270 32 72 14 re f* 0.50000 0.50000 0.50000 rg BT /F2 9 Tf 10.80000 TL ET BT 1 0 0 1 301.50000 35 Tm (25) Tj T* ET Q endstream endobj 13 0 obj << /Filter /FlateDecode /Resources << /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x18 14 0 R >> >> /Length 28 /Group << /Type /Group /S /Transparency /CS /DeviceRGB /I true >> /BBox [ 78 746 96 765 ] /Type /XObject /Subtype /Form >> stream x+O4PH/VЯ0Pp 0 endstream endobj 14 0 obj << /Filter /FlateDecode /Resources 15 0 R /Length 107 /Type /XObject /BBox [ 78 746 96 765 ] /Subtype /Form >> stream xe AC̬wʠ =p,?]%+H-
Jc "82w8VSnGW;"
endstream
endobj
15 0 obj
<<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
>>
endobj
16 0 obj
<<
/Filter /FlateDecode
/Resources <<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
/XObject <<
/x15 17 0 R
>>
>>
/Length 28
/Group <<
/Type /Group
/S /Transparency
/CS /DeviceRGB
/I true
>>
/BBox [ 67 752 84 775 ]
/Type /XObject
/Subtype /Form
>>
stream
x+O4PH/VЯ04Up
0
endstream
endobj
17 0 obj
<<
/Filter /FlateDecode
/Resources 18 0 R
/Length 228
/Type /XObject
/BBox [ 67 752 84 775 ]
/Subtype /Form
>>
stream
xeQKn!s ?FPav6R٪TS.
b];15YyR
{7QL.\:Rv/x9l+L7h%1!}i/AI(kz"U&,YO![R hg{3}4/GyYF:!w}Gn+'xJcO9i뽼_-:`
endstream
endobj
18 0 obj
<<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
>>
endobj
19 0 obj
<<
/Filter /FlateDecode
/Resources <<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
/XObject <<
/x24 20 0 R
>>
>>
/Length 28
/Group <<
/Type /Group
/S /Transparency
/CS /DeviceRGB
/I true
>>
/BBox [ 112 751 500 772 ]
/Type /XObject
/Subtype /Form
>>
stream
x+O4PH/VЯ02Qp
0
endstream
endobj
20 0 obj
<<
/Filter /FlateDecode
/Resources 21 0 R
/Length 56490
/Type /XObject
/BBox [ 112 751 500 772 ]
/Subtype /Form
>>
stream
xtIJ5*|^~x?P9)<<ҥ+kh4}/?>]漿վ]Z Ǭ57W'b~?Kwk6:>rAニxeG1k-/LfߗA̺(egk5>
=KO1{Vux}Ol|_s؟|*>5=k|*a5x}On :97~1s7rX {|>IQQo6|'\#x_ڽC}M7(췀(N
سW#^Ň}|zblnB'\o=r;$s:z-
V3+έ昵 WD/nl ;q"3Pg휅\3C`k7760c9-Cȸ