1. Wild patterns: Ten years after the rise of adversarial machine learning;Biggio;Pattern Recognition,2018
2. Towards evaluating the robustness of neural networks;Carlini,2017
3. Chen, B., Carvalho, W., Baracaldo, N., Ludwig, H., Edwards, B., Lee, T., Molloy, I., Srivastava, B., 2018. Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering. http://arxiv.org/abs/1811.03728.
4. Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks;Chen,2019
5. Chen, X., Liu, C., Li, B., Lu, K., Song, D., 2017. Targeted backdoor attacks on deep learning systems using data poisoning. https://arxiv.org/abs/1712.05526v1.