1. 2023. CrossCert. https://github.com/kio-cs/CrossCert
2. Tom B Brown Dandelion Mané Aurko Roy Martín Abadi and Justin Gilmer. 2017. Adversarial patch. arXiv preprint arXiv:1712.09665.
3. Towards Practical Certifiable Patch Defense with Vision Transformer
4. ImageNet: A large-scale hierarchical image database
5. Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2021. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. In International Conference on Learning Representations. https://openreview.net/forum?id=YicbFdNTTy