Clustering Adversarial Robust Models

Neural Information Processing Systems 

Projected 23] adds smaller .