Revisiting the Robust Generalization of Adversarial Prompt Tuning