Abstract: Highlights•A novel adversarial defense exploring model properties to improve DNNs’ robustness•Multiple paths augment DNNs for diverse features adaptive to adversarial inputs•An orthogonality loss and a margin-maximization loss contribute to DNNs’ diversity•The proposed method outperforms the non-data-augmented adversarial defenses•Compatibility with the data-augmented techniques, leading to improved robustness
Loading