On Neural Network approximation of ideal adversarial attack and convergence of adversarial training

Open in new window