Scaling provable adversarial defenses

Eric Wong, Frank Schmidt, Jan Hendrik Metzen, J. Zico Kolter

Neural Information Processing Systems 

Third, we show how to further improve robust error through cascade models.