1. Andriushchenko, M., Croce, F., Flammarion, N., & Hein, M. (2020). Square attack: A query-efficient black-box adversarial attack via random search. In ECCV (Vol. 12368, pp. 484–501).
2. Athalye, A., Engstrom, L., Ilyas, A., & Kwok, K. (2018). Synthesizing robust adversarial examples. In ICML (Vol. 80, pp. 284–293).
3. Bai, Y., Mei, J., Yuille, A. L., & Xie, C. (2021). Are transformers more robust than cnns? In NeurIPS (pp. 26831–26843).
4. Bai, J., Yuan, L., Xia, S., Yan, S., Li, Z., & Liu, W. (2022). Improving vision transformers by revisiting high-frequency components. arXiv preprint arXiv:2204.00993.
5. Benz, P., Ham, S., Zhang, C., Karjauv, A., & Kweon, I. S. (2021). Adversarial robustness comparison of vision transformer and mlp-mixer to cnns. In BMVC (p. 25).