Fetching the paper…

Double Backpropagation for Training Autoencoders against Adversarial Attack · Around