Sun Dec 8th through Sat the 14th, 2019 at Vancouver Convention Center
The paper proposes a certified defense method by adding Gaussian noise and a stability training approach to further improve robustness. After the rebuttal, the authors addressed most of the concerns and the reviewers agreed that this paper has some interesting contributions. Reviewer 1 still has some concerns about the comparison with TRADES and we hope the authors can address this in the final version. Also, although we are judging the novelty of this paper assuming there is no (Cohen et al), the authors should cite and discuss about (Cohen et al) in the camera ready version.