Supplementary Material: Toward Efficient Robust Training against Union of ℓ p Threat Models