If an adversarial attack uses 'perturbations'—tiny invisible changes—to trick a facial recognition system, which specific layer of the neural network should be hardened to block these input-based exploits?
Community Answers
Sign in to open profiles and full community answers.
No community answers yet. Be the first to submit one.