Joint adversarial training shows limited effectiveness, as training against multiple attacks doesn't significantly outperform training against a single one. This raises concerns for practitioners who may need to choose specific techniques to defend against. The hope lies in establishing benchmarks to guide progress and potentially bounding the space of attacks, although novel methods continue to emerge, complicating the landscape.