Robustness Guarantees for Adversarially Trained Neural Networks

Neural Information Processing Systems 

This allows us to give a convergence guarantee for the inner-loop PGD attack.