A Additional plots for experiments

Neural Information Processing Systems 

Exact numbers for all the curves are in Appendix S. In this section we present the plots of our experiments with WideResNet28-10. In Figure 9 we plot all methods, including multi-step methods, and report the clean accuracy as well with dashed lines. As mentioned in the main paper, we observe that CO seems to be more difficult to prevent for WideResNet. Legend is shared among all plots. We use α = 8 for both ϵ radii.