Fig. 2From: Smooth adversarial examplesFor a given attack (denoted by an asterisk and bold typeface), the adversarial image with the strongest distortion D over MNIST. In green, the attack succeeds; in red, it failsBack to article page