1. Synthesizing robust adversarial examples;Athalye,2018
2. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples;Athalye,2018
3. Wasserstein generative adversarial networks;Arjovsky,2017
4. Deep speech 2: End-to-end speech recognition in english and mandarin;Amodei,2016
5. Brendel W, Rauber J, Bethge M. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248, 2017.