chop
chop copied to clipboard
Adaptive penalty multipliers
Similar to the Carlini & Wagner attack, we'd like the alpha to be defined datapoint wise in the penalty constraints. Ideally, given a datapoint we should be able to perform binary search to find the smallest alpha which swings a label for a given adversary.