1. Brendel W., Rauber J., Bethge M. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models[J]. arXiv preprint arXiv:1712.04248, 2017.
2. Towards evaluating the robustness of neural networks[C];Carlini,2017
3. Certified adversarial robustness via randomized smoothing[C];Cohen,2019
4. Boosting adversarial attacks with momentum[C];Dong,2018
5. Dong Y., Pang T., Su H., et al. Evading defenses to transferable adversarial examples by translation-invariant attacks[C], Proceedings of the IEEE/CVF conference on computer vision and pattern recognition. 2019: 4312–4321.