The problem of adversarial examples has shown that modern Neural Network (NN)
models could be rather fragile. Among the more established techniques to solve
the problem, one is to require the model to be {\it $\epsilon$-adversarially
robust} (AR); that is, to require the model not to c