@misc{indiciae1c3191d52870, title = {Feature Purification: How Adversarial Training Performs Robust Deep Learning}, author = {Zeyuan Allen-Zhu and Yuanzhi Li}, year = {2022}, url = {https://arxiv.org/abs/2005.10190}, note = {Source identifier: 2005.10190} }