IJCAI-19 Alibaba Adversarial AI Challenge
Defense: Ensemble adversarial training on both black-box and white-box generated examples,also include DDN and TRADES adversarial training.
Target Attack: Black box attack using MIFGSM,PGD,DDN,CW_l2,etc.
Untarget Attack: To generate adversarial examples, Robust models are used to attack the target model with a variety of attack methods.