Adversarial Training is a Form of Data-dependent Operator Norm Regularization

NeurIPS 2020