How Many Bits Does it Take to Quantize Your Neural Network?

We provide an example for the non-monotonicity of robustness and improve our experimental evaluation, which now includes a comparison between encodings and against a recently published gradient descent–based method for quantized networks.

We provide a comparison between various SMT-solvers.

Keyphrases: adversarial attacks, bit-vectors, Quantized Neural Networks, SMT solving

