Towards Compositional Adversarial Robustness: Generalizing Adversarial Training to Composite Semantic Perturbations | Read Paper on Bytez