1. Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow. 2018. Thermometer encoding: One hot way to resist adversarial examples. In International conference on learning representations (ICLR). ICLR, Vancouver, CANADA, 22 pages.
2. Adversarial Examples Are Not Easily Detected
3. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (S&P). IEEE, San Jose, CA, United States, 39–57.
4. Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, and Nasser Nasrabadi. 2019. Fast geometrically-perturbed adversarial faces. In 2019 IEEE Winter Conference on Applications of Computer Vision (WACV). IEEE, Waikoloa Village, HI, USA, 1979–1988.
5. Debayan Deb, Jianbang Zhang, and Anil K Jain. 2019. Advfaces: Adversarial face synthesis. In 2020 IEEE International Joint Conference on Biometrics (IJCB). IEEE, Online, 1–10.