1. Spatially transformed adversarial examples;Xiao,2018
2. One pixel attack for fooling deep neural networks;Su;IEEE Trans. Evolut. Computat.,2019
3. The limitations of deep learning in adversarial settings;Papernot,2016
4. Unrestricted adversarial examples via semantic manipulation;Bhattad,2020
5. Practical black-box attacks against machine learning;Papernot,2017