In this very short video (as supplementary material for the IV'20 paper), we demonstrate the performance between a DNN trained using provably robust training techniques (as proposed in the paper) and a DNN training using standard techniques.
As an example, by separately applying single-step FGSM attacks on two networks with the same attack intensity (the actual attacks are different), one can observe that, for standard DNN that predicts the centre-of-lane, the output prediction can greatly vary. This does not happen for the provably robust training network.