Cao and Gong introduce region-based classification as defense against adversarial examples. In particular, given an input (benign test input or adversarial example), the method samples random point in the neighborhood and classifies the test sample according to the majority vote of the obtained labels.
What is your opinion on the summarized work? Or do you know related work that is of interest? Let me know your thoughts in the comments below: