So, the target is to train on the clean dataset, like ImageNet, and show robustness on the corrupt dataset, like ImageNet-C, right?