Generalizing randomized smoothing for pointwise-certified defenses to data poisoning attacks

Open in new window