1. Are labels required for improving adversarial robustness?;Alayrac,2019
2. Square attack: A query-efficient black-box adversarial attack via random search;Andriushchenko,2020
3. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples;Athalye,2018
4. Synthesizing robust adversarial examples;Athalye,2018
5. Thwarting adversarial examples: An L_0-robust sparse Fourier transform;Bafna,2018