1. Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: Bengio Y, LeCun Y (eds) ICLR
2. Krizhevsky A, Sutskever I, Hinton GE (2012) "Imagenet classification with deep convolutional neural networks." Advances in neural information processing systems 25
3. Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv:1312.6199
4. Bhattad A, Chong MJ, Liang K, Li B, Forsyth DA (2020) Unrestricted adversarial examples via semantic manipulation. In: ICLR
5. Miller B, Kantchelian A, Afroz S, Bachwani R, Dauber E, Huang L, Tschantz MC, Joseph AD, Tygar JD (2014) Adversarial active learning. In: Proceedings of the 2014 workshop on artificial intelligent and security workshop (pp. 3-14)