Skip to main content
. 2021 Aug 24;12:5104. doi: 10.1038/s41467-021-25342-8

Fig. 3. Adversarial attacks applied to a toy potential.

Fig. 3

a Evolution of the PES of a 2D double well predicted by an NN committee. Adversarial examples (black dots) are distortions from original training data (white dots) or past adversarial examples (gray dots) that maximize the adversarial loss Ladv. The plotting intervals are [−1.5, 1.5] × [−1.5, 1.5] for all graphs. The generation of the NN committee is shown in the top left corner of each graph. b Evolution of the root mean square error (RMSE), number of training points, and energy of the data points sampled using the adversarial attack strategy (red) or by randomly distorting the training data (blue). The solid line is the median from more than 100 experiments, and the shaded area is the interquartile region.