1. Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)
2. Su, J., Vargas, D.V., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828–841 (2019)
3. Fan, L., et al.: Explore gap between 3D DNN and human vision utilizing fooling point cloud generated by MEHHO. Secur. Commun. Netw. 2023 (2023)
4. Hu, S., Nalisnick, E., Welling, M.: Adversarial defense via image denoising with chaotic encryption. arXiv preprint arXiv:2203.10290 (2022)
5. Tobia, J., et al.: AGS: Attribution guided sharpening as a defense against adversarial attacks. In: Advances in Intelligent Data Analysis XX: 20th International Symposium on Intelligent Data Analysis, Proceedings. Springer, Cham (2022)