the main paper, with one additional reference for this rebuttal. 3 Reviewer 1: " a major takeaway I get is that the PGD attack seems to provide an okay approximation of robustness