Lipschitz-Margin Training: Scalable Certification of Perturbation Invariance for Deep Neural Networks

Yusuke Tsuzuku, Issei Sato, Masashi Sugiyama

Neural Information Processing Systems 

One approach to defend from adversarial perturbations is to mask gradients.