1. Square attack: A query-efficient black-box adversarial attack via random search;Andriushchenko,2020
2. Brendel, W., Rauber, J., Bethge, M., 2018. Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In: ICLR.
3. On evaluating adversarial robustness;Carlini,2019
4. Carlini, N., Wagner, D.A., 2017. Towards Evaluating the Robustness of Neural Networks. In: S&P. pp. 39–57.
5. Chen, G., Chen, S., Fan, L., Du, X., Zhao, Z., Song, F., Liu, Y., 2021. Who is Real Bob? Adversarial Attacks on Speaker Recognition Systems. In: S&P. pp. 694–711.