Adversarial Training and Robustness for Multiple Perturbations

Florian Tramer, Dan Boneh

Neural Information Processing Systems 

For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability.