1. Athalye A, Carlini N, Wagner D (2018) Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. arXiv:1802.00420
2. Balduzzi D, Frean M, Leary L, Lewis JP, Ma KW, Mcwilliams B (2017) The shattered gradients problem: if resnets are the answer, then what is the question?. Neural and evolutionary computing. arXiv:1702.08591
3. Brendel W, Rauber J, Bethge M (2017) Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. Machine learning. arXiv:1712.04248
4. Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 ieee symposium on security and privacy (sp). IEEE, pp 39–57
5. Chan A, Tay Y, Ong YS, Fu J (2019) Jacobian adversarially regularized networks for robustness