1. Brown, T., Mane, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch (2017). arXiv:1712.09665
2. Chiang, P.-y., Ni, R., Abdelkader, A., Zhu, C., Studor, C., Goldstein, T.: Certified defenses for adversarial patches. In: ICLR (2020)
3. Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: Security and Privacy (2017). arXiv:1608.04644 [cs.CR]
4. Deotte, C.: How to choose CNN Architecture MNIST (2018). https://www.kaggle.com/cdeotte/how-to-choose-cnn-architecture-mnist
5. Devries, T., Taylor, G.W.: Improved regularization of convolutional neural networks with cutout (2017). arXiv:1708.04552 [cs.CV]