This paper presents a framework to improve the robustness of deep clustering to adversarial attack. This problem is important, and the method is sound and backed by extensive experimentation. However, the paper is in part not entirely clear and hard to reproduce with the current level of details, and a major rewriting is required to clarify the details of this method.