Expectation over transformation
Appearance
Expectation over transformation
A method for strengthening adversarial examples to remain adversarial under image transformations that occur in the real world, such as angle and viewpoint changes. EOT models these perturbations within the optimization procedure. Rather than optimizing the log-likelihood of a single example, EOT uses a chosen distribution of transformation functions that take an input controlled by the adversary to the “true” input perceived by the classifier.
Source: NIST AI 100-2e2025 | Category: