Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers Hadi Salman, Greg Y ang

Neural Information Processing Systems 

In this paper, we employ adversarial training to improve the performance of randomized smoothing.