1. Intriguing properties of neural networks;Szegedy,2013
2. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples;Athalye,2018
3. On adaptive attacks to adversarial example defenses;Tramer,2020
4. Countering adversarial images using input transformations;Guo,2017
5. Towards deep learning models resistant to adversarial attacks;Madry,2017