1. Square attack: a query-efficient black-box adversarial attack via random search;Andriushchenko,2020
2. Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples;Athalye,2018
3. Towards evaluating the robustness of neural networks;Carlini,2017
4. Similarity estimation techniques from rounding algorithms;Charikar,2002