Fig. 2From: Machine learning through cryptographic glasses: combating adversarial attacks by key-based diversified aggregationClassifier training: a traditional classifier has an access to training data samples \(\{\boldsymbol {\mathrm {x}}_{i}, c_{i}\}_{i=1}^{M}\) generated from Pχ(x). The classifier learns a set of parameters θ to output a decision \(\hat {c} \in \{1,..., M_{c}\}\) or to reject an input (\(\varnothing \))Back to article page