Code Github Adversarial training on purification (AToP): Advancing both robustness and generalization (ICLR 2024)