Toward Efficient Robust Training against Union of ℓ p Threat Models

Neural Information Processing Systems 

MSD) that also uses multi-step ( k = 50) adversarial attacks to generate adversaries for training. However, these methods, owing to their requirement of great number of adversarial training steps as compared to a regular setting for multi-step adversarial training procedure (10 steps), are computationally inefficient.