1 paper
Lin Li, Yifei Wang, Chawin Sitawarin +1
Existing works have made great progress in improving adversarial robustness, but typically test their method only on data from the same distribution as the training data, i.e. in-d…