Figure 1: Robust accuracy of models againstAU-TOATTACK[16]onCIFAR-10with` perturbations