1. The mnist database of handwritten digits. http://yann. lecun.com/exdb/mnist/ ..
2. Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., Chiang, M., Mittal, P., and Hein, M. Robust-bench: a standardized adversarial robustness benchmark. In NeurIPS (2021).
3. Croce, F., and Hein, M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In ICML (2020).
4. Engstrom, L., Ilyas, A., Salman, H., Santurkar, S., and Tsipras, D. Robustness (python library), 2019.
5. Fidel, G., Bitton, R., and Shabtai, A. When explainability meets adversarial learning: Detecting adversarial examples using shap signatures. In IJCNN (2020).