Here,wedescribethedetailedrealizationoftheLine-Search&Momentum-PGD(LM-PGD)method. ComparedwiththecommonlyusedPGDmethodoftheformfollowing δ

Neural Information Processing Systems 

Our PMs are continuous and path-independent, overcoming the deficiencyofpreviousworks[47]. Moreover, there is still room for improvement in our approach and related works. This paper mainly focuses on adversarial robustness regarding white-box attacks generated by the first-order gradient-based methods. When employing our MAIL in real-world applications, it may lead to over-confidence regarding many other attacks, e.g., provable attacks [5], black-box attacks [6], and physical attacks [25]. For data assigned with larger weights, the resulting model would be more robust when encounters similar dataduring thetest. This unfairness problem seems inevitable forareweighted learning framework, which will interest our further study.