{
  "link": "https://arxiv.org/abs/2103.01946",
  "name": "Fixing Data Augmentation to Improve Adversarial Robustness",
  "authors": "Sylvestre-Alvise Rebuffi, Sven Gowal, Dan A. Calian, Florian Stimberg, Olivia Wiles, Timothy Mann",
  "additional_data": false,
  "number_forward_passes": 1,
  "dataset": "cifar10",
  "venue": "arXiv, Mar 2021",
  "architecture": "WideResNet-28-10",
  "eps": "8/255",
  "clean_acc": "87.33",
  "reported": "60.73",
  "autoattack_acc": "60.75",
  "external": "60.73",
  "footnote": "It uses additional 1M synthetic images in training. 60.73% robust accuracy is due to the original evaluation (AutoAttack + MultiTargeted)",
  "unreliable": false
}
