1. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples;Athalye,2018
2. Recent advances in adversarial training for adversarial robustness;Bai,2021
3. Automatic vehicle counting from video for traffic flow analysis;Bas,2007
4. Tutorials on testing neural networks;Berthier,2021
5. Buckman, J., Roy, A., Raffel, C., & Goodfellow, I. (2018). Thermometer encoding: One hot way to resist adversarial examples. In International conference on learning representations.