We show that when taking into account also the image domain $[0,1]^d$,\nestablished $l_1$-projected gradient descent (PGD) attacks are suboptimal as\nthey do not consider that the effective threat model is the intersection of the\n$l_1$-ball and $[0,1]^d$. We study the expected sparsity of the steepest\ndescent step for this effective threat model and show that the exact projection\nonto this set is computationally feasible and yields better performance.\nMoreover, we propose an adaptive form of PGD which is highly effective even\nwith a small budget of iterations. Our resulting $l_1$-APGD is a strong\nwhite-box attack showing that prior works overestimated their $l_1$-robustness.\nUsing $l_1$-APGD for adversarial training we get a robust classifier with SOTA\n$l_1$-robustness. Finally, we combine $l_1$-APGD and an adaptation of the\nSquare Attack to $l_1$ into $l_1$-AutoAttack, an ensemble of attacks which\nreliably assesses adversarial robustness for the threat model of $l_1$-ball\nintersected with $[0,1]^d$.\n