{
  "link": "https://arxiv.org/abs/2103.01946",
  "name": "Fixing Data Augmentation to Improve Adversarial Robustness",
  "authors": "Sylvestre-Alvise Rebuffi, Sven Gowal, Dan A. Calian, Florian Stimberg, Olivia Wiles, Timothy Mann",
  "additional_data": false,
  "number_forward_passes": 1,
  "dataset": "cifar10",
  "venue": "arXiv, Mar 2021",
  "architecture": "WideResNet-106-16",
  "eps": "8/255",
  "clean_acc": "88.50",
  "reported": "64.58",
  "autoattack_acc": "64.64",
  "external": "64.58",
  "footnote": "It uses additional 1M synthetic images in training. 64.58% robust accuracy is due to the original evaluation (AutoAttack + MultiTargeted)",
  "unreliable": false
}
