Adversarially Robust Learning with Uncertain Perturbation Sets

Neural Information Processing Systems 

In many real-world settings exact perturbation sets to be used by an adversary are not plausibly available to a learner.