In this work, we consider the scenario when the 1 manifold information is exact and show that this information can be very useful for improving robustness to novel

Neural Information Processing Systems 

How DMA T can be exploited for standard tasks/datasets? PGD should not be viewed as the strongest attack for evaluation. Results are shown in Table B. Results are presented in the last column of Table B. DMA T Other strong baselines such as TRADES should be included in the main paper . The notion of "manifold" should be clarified. We will explain this further in the paper.