1. Cai, Z., Song, C., Krishnamurthy, S., Roy-Chowdhury, A., Asif, S.: Blackbox attacks via surrogate ensemble search. In: NeurIPS (2022)
2. Chen, H., Zhang, Y., Dong, Y., Zhu, J.: Rethinking model ensemble in transfer-based adversarial attacks. CoRR abs/2303.09105 (2023)
3. Chen, J., Wu, X., Guo, Y., Liang, Y., Jha, S.: Towards evaluating the robustness of neural networks learned by transduction. In: ICLR. OpenReview.net (2022)
4. Cheng, S., Dong, Y., Pang, T., Su, H., Zhu, J.: Improving black-box adversarial attacks with a transfer-based prior. In: NeurIPS, pp. 10932–10942 (2019)
5. Dong, Y., et al.: Boosting adversarial attacks with momentum. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2018)