DISCO: Adversarial Defense with Local Implicit Functions

Neural Information Processing Systems 

The problem of adversarial defenses for image classification, where the goal is to robustify a classifier against adversarial examples, is considered.