Train classifiers and attackers multiple times to get bounds on model accuracy and attack power, providing more reliable results