1. Vito Walter Anelli, Alejandro Bellogín, Yashar Deldjoo, Tommaso Di Noia, and Felice Antonio Merra. 2021. MSAP: Multi-Step Adversarial Perturbations on Recommender Systems Embeddings. FLAIRS 34 (Apr. 2021).
2. Vito Walter Anelli, Yashar Deldjoo, Tommaso Di Noia, Daniele Malitesta, and Felice Antonio Merra. 2021. A study of defensive methods to protect visual recommendation against adversarial manipulation of images. In SIGIR, ACM.
3. Vito Walter Anelli, Yashar Deldjoo, Tommaso Di Noia, and Felice Antonio Merra. 2021. A Formal Analysis of Recommendation Quality of Adversarially-trained Recommenders. In CIKM.
4. Anish Athalye Nicholas Carlini and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In ICML. 274–283.
5. Latent Cross