Abstract: In recent years, it has been widely believed that deep neural networks are vulnerability to adversarial sample attacks, especially under the white-box attack mode, where the attack effects ...