Besting the Black-Box: Barrier Zones for Adversarial Example Defense
Adversarial machine learning defenses have primarily been focused on mitigating static, white-box attacks.However, it remains an open question whether such defenses are robust under an adaptive black-box adversary.In this paper, we specifically focus on the black-box threat model and make the following contributions: First we develop an enhanced ad