1. Bousquet, O., & Elisseeff, A. (2002). Stability and generalization. The Journal of Machine Learning Research, 2, 499–526.
2. Carlini, N. & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In 2017 IEEE symposium on security and privacy (sp), pp. 39–57.
3. Carlini, N. & Wagner, D. (2018). Audio adversarial examples: Targeted attacks on speech-to-text. (2018) IEEE security and privacy workshops (spw) (1–7).
4. Chen, Y., Ren, Q. & Yan, J. (2022). Rethinking and improving robustness of convolutional neural networks: A shapley value-based approach in frequency domain. Advances in neural information processing systems.
5. Croce, F. & Hein, M. (2020). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. ICML.