Abstract: Highlights•We observe that adversarial detection is sensitive to the perturbation level.•We train a shallow autoencoder to find two key features from adversarial examples.•We propose a lightweight and unsupervised adversarial detector.
Loading