1. [n. d.]. 2022 Incident Response Report. https://www.paloaltonetworks.com/unit42/2022-incident-response-report
2. Stanley Bak. 2021. nnenum: Verification of ReLU Neural Networks with Optimized Abstraction Refinement. In NASA Formal Methods Symposium. Springer.
3. Branch and Bound for Piecewise Linear Neural Network Verification;Bunel Rudy;J. Mach. Learn. Res.,2020
4. Nicholas Carlini, Florian Tramer, Krishnamurthy Dj Dvijotham, Leslie Rice, Mingjie Sun, and J Zico Kolter. 2023. (Certified!!) Adversarial Robustness for Free!. In The Eleventh International Conference on Learning Representations. https://openreview.net/forum?id=JLg5aHHv7j
5. Nicholas Carlini and David Wagner. 2017. Magnet and" efficient defenses against adversarial attacks" are not robust to adversarial examples. arXiv preprint arXiv:1711.08478 (2017).