Source code for the paper:
Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations
Florian Tramèr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot and Jörn-Henrik Jacobsen
https://arxiv.org/abs/2002.04599
The Demo notebook shows how to load pre-computed invariance examples for the l0 and linf norms.
The folders l0 and linf contain code for generating such invariance examples.