F Tramer,
D Boneh - Advances in neural information …, 2019 - proceedings.neurips.cc
Defenses against adversarial examples, such as adversarial training, are typically tailored to
a single perturbation type (eg, small $\ell_\infty $-noise). For other perturbations, these …