1. Maksym Andriushchenko , Francesco Croce , Nicolas Flammarion , and Matthias Hein . 2019. Square Attack: a query-efficient black-box adversarial attack via random search. CoRR abs/1912.00049 ( 2019 ). arXiv:1912.00049 http://arxiv.org/abs/1912.00049 Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion, and Matthias Hein. 2019. Square Attack: a query-efficient black-box adversarial attack via random search. CoRR abs/1912.00049 (2019). arXiv:1912.00049 http://arxiv.org/abs/1912.00049
2. Shumeet Baluja . 2017 . Hiding Images in Plain Sight: Deep Steganography. In Advances in Neural Information Processing Systems, I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R . Garnett (Eds.) , Vol. 30 . Curran Associates, Inc. https://proceedings.neurips.cc/paper/ 2017/file/838e8afb1ca34354ac209f53d90c3a43-Paper.pdf Shumeet Baluja. 2017. Hiding Images in Plain Sight: Deep Steganography. In Advances in Neural Information Processing Systems, I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30. Curran Associates, Inc. https://proceedings.neurips.cc/paper/2017/file/838e8afb1ca34354ac209f53d90c3a43-Paper.pdf
3. Branch and Bound for Piecewise Linear Neural Network Verification;Bunel Rudy;Journal of Machine Learning Research,2020
4. Francesco Croce , Maksym Andriushchenko , Vikash Sehwag , Nicolas Flammarion , Mung Chiang , Prateek Mittal , and Matthias Hein . 2020. RobustBench: a standardized adversarial robustness benchmark. CoRR abs/2010.09670 ( 2020 ). arXiv:2010.09670 https://arxiv.org/abs/2010.09670 Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein. 2020. RobustBench: a standardized adversarial robustness benchmark. CoRR abs/2010.09670 (2020). arXiv:2010.09670 https://arxiv.org/abs/2010.09670
5. Francesco Croce and Matthias Hein . 2019. Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack. CoRR abs/1907.02044 ( 2019 ). arXiv:1907.02044 http://arxiv.org/abs/1907.02044 Francesco Croce and Matthias Hein. 2019. Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack. CoRR abs/1907.02044 (2019). arXiv:1907.02044 http://arxiv.org/abs/1907.02044