Evaluating need for adversarial training data given algorithmic defense methods against adversarial attacks
This study set up a baseline image classifier for images of digits and attacked the images using the fast gradient sign method, and hypothesized that introducing adversarial training for this classifier would significantly improve downstream classification accuracy in all three algorithmic defense settings.