YOPO reduces adversarial training time by one forward/backward pass per group of updates.
problem Adversarial training's high computational cost limits deep learning's robustness.
method YOPO uses the Pontryagin's Maximal Principle to limit propagation to the first layer.
result YOPO achieves comparable defense accuracy with significantly less computational time.