“…y k {p (y|x * )}, k = 1, 2, • • • , K, (37) so { y p (x * ) = y t , L (x, α, g) ≤ L T y p (x * ) ̸ = y t , L (x, α, g) > L T (38)where y p represents the predicted class of the model for the adversarial example, and y t represents the true class.APPENDIX B PROOF OF PROPOSITION 2We denote p (x * ) as p, and substitute (30) into the cross entropy loss of the model to obtainL − β) • δ k,l + β • u(k)) • log 2 (p k ) = (1 − β) [ − K ∑ k=1 δ k,l log 2 (p k ) )log 2 (p k ) ] = (1 − β) • L (x * , l) + β • L (x * , u)(39) …”