We show that defensive distillation is not secure: it is no more resistant to targeted misclassification attacks than unprotected neural networks.
No takes yet. Share an insight, caveat, or question.
Carlini et al. (2016) studied this question.
Synapse has enriched 3 closely related papers on similar clinical questions. Consider them for comparative context: