1. Anish Athalye, Logan Engstrom, Andrew Ilyas, Kevin Kwok. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397, 2017.
2. Wieland Brendel, Jonas Rauber, Matthias Bethge, Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248, 2017.
3. Towards evaluating the robustness of neural networks;Carlini,2017
4. Android hiv: A study of repackaging malware for evading machine-learning detection;Chen;IEEE Transactions on Information Forensics and Security,2019