1. Towards evaluating the robustness of neural networks;Carlini,2017
2. Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models;Chen,2017
3. ImageNet: a large-scale hierarchical image database;Deng,2009
4. Boosting adversarial attacks with momentum;Dong,2018
5. Evading defenses to transferable adversarial examples by translation-invariant attacks;Dong,2019