Really interesting paper exploring adversarial inputs to ML models: https://arxiv.org/abs/1905.02175 They conclude: * It's a property of the input data, not the training * You can even train a model on non-robust features and obtain a model that works well on the original input data!