Dual Manifold Adversarial Robustness: Defense against L p and non-L p Adversarial Attacks

Neural Information Processing Systems 

However, it often degrades the model performance on normal images and more importantly, the defense does not generalize well to novel attacks.