1. Abadi, M., et al.: Tensorflow: large-scale machine learning on heterogeneous systems, 1 (2015). tensorflow.org
2. Baluja, S., Fischer, I.: Learning to attack: adversarial transformation networks. In: AAAI (2018)
3. Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy (2017)
4. Cisse, M., Bojanowski, P., Grave, E., Dauphin, Y., Usunier, N.: Parseval networks: improving robustness to adversarial examples. In: ICML (2017)
5. Fawzi, A., Moosavi-Dezfooli, S., Frossard, P., Soatto, S.: Classification regions of deep neural networks. arXiv abs/1705.09552 (2017)