fdb55ce855129e05da8374059cc82728-Supplemental.pdf

Neural Information Processing Systems 

A.1 Fullexperimentalresults In this section we provide the full experimental results that extend the results demonstrated in the Section 4.2. Table 8 demonstrates the evaluation on 16 robustly trained CIFAR10 models from RobustBench [28] that was summarized in the Table 2. We consider four configurations of the attack for each of the models. SA and AA correspond to the update size schedules proposed by Andriushchenko et al.[1]and Croce and Hein[2]respectively. "Uni" denotes sampling the color fortheupdateuniformly. A.2 Meta-trainingtheControllers The meta-training of controllers was described in Section 3 and Section 4.1.