1. Albert R, Jeong H, Barabási AL (2000) Error and attack tolerance of complex networks. Nature 406(6794):378–382
2. Athalye A, Carlini N (2018) On the robustness of the CVPR 2018 white-box adversarial example defenses. CoRR abs/1804.03286
3. Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: ICML, pp 274–283
4. Bojchevski A, Günnemann S (2019) Certifiable robustness to graph perturbations. In: NeurIPS, pp 8317–8328
5. Carlini N et al (2019) On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705