virtual adversarial training
By Miyato et al.:
A perturbation $\Delta x = \mathrm{arg max}_{\Delta x} \mathrm{KL}(p(y \vert x) \vert \vert p(y \vert x + \Delta x))
#needs-expanding
Backlinks
scalable-uncertainties-from-deep-ensembles
Basically use conventional [[fast gradient sign method]], or [[virtual adversarial training]].