Fig. 2From: Deep neural rejection against adversarial examplesOur defense-aware attack against an RBF SVM with rejection, on a 3-class bi-dimensional classification problem. The initial sample x0 and the adversarial example x⋆ are respectively represented as a red hexagon and a green star, while the ℓ2-norm perturbation constraint ∥x0−x′∥2≤ε is shown as a black circle. The left plot shows the decision region of each class, along with the reject region (in white). The right plot shows the values of the attack objective Ω(x) (in colors), which correctly enforces our attacks to avoid the reject regionBack to article page