Harm Berntsen

We don’t have enough information about this author to calculate their statistics. If you think this is an error let us know.
Learn More
We introduce a novel type of artificial neural network structure and training procedure that results in networks that are provably, quantitatively more robust to adversarial samples than classical, end-to-end trained classifiers. The main idea of our approach is to force the network to make predictions on what the given instance of the class under(More)
  • 1