[1]
J. Fan and W. Li, “Adversarial Training and Provable Robustness: A Tale of Two Objectives”, AAAI, vol. 35, no. 8, pp. 7367-7376, May 2021.