Abstract: Highlights•We propose a network architecture enabling global verification in a feasible way.•Our verification approach can find all adversarial dangerous regions (ADRs).•The proposed filter can find ADRs with meaningful adversarial examples.
Loading