In this work, we reveal that the full gradient component in SAM’s adversarial weight perturbation does not contribute to generalization and, in fact, has undesirable effects. We then propose an ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results