1. Aydin, A., Sen, D., Karli, B.T., Hanoglu, O., Temizel, A.: Imperceptible adversarial examples by spatial chroma-shift. In: ADVM, pp. 8–14 (2021)
2. Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. In: S &P (2017)
3. Chen, K., Guo, S., Zhang, T., Li, S., Liu, Y.: Temporal watermarks for deep reinforcement learning models. In: AAMAS, pp. 314–322 (2021)
4. Chen, K., et al.: BADPRE: task-agnostic backdoor attacks to pre-trained NLP foundation models. In: ICLR (2022)
5. Croce, F., et al.: Robustbench: a standardized adversarial robustness benchmark. In: NeurIPS (2021)