Supplementary Material: Toward Efficient Robust Training against Union of l Threat Models