1. Lecture Notes in Computer Science;M Andriushchenko,2020
2. Cai, Z., Song, C., Krishnamurthy, S., Roy-Chowdhury, A., Asif, S.: Blackbox attacks via surrogate ensemble search. In: NeurIPS (2022)
3. Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy, pp. 39–57. IEEE Computer Society (2017)
4. Croce, F., Hein, M.: Minimally distorted adversarial examples with a fast adaptive boundary attack. In: ICML. vol. 119. Proceedings of Machine Learning Research, pp. 2196–2205. PMLR (2020)
5. Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML, vol. 119. Proceedings of Machine Learning Research, pp. 2206–2216. PMLR (2020)