Research Article

Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples

Figure 8

The training architecture of ResGN. The optimization of ResGN is driven by minimizing a joint loss containing pixel loss, texture loss, and semantic loss. The latter two losses are provided by any pretrained network.