Abstract: Highlights•Adversaries only change a portion of elements of each activation to realize attack.•An element-wise activation scaling method is proposed to improve CNNs’ robustness.•Extensive experimental results show our method significantly improves the robustness.•We have open-sourced the code at https://github.com/ieslab-ynu/EWAS.
Loading