1. Lei Bu , Zhe Zhao , Yuchao Duan , and Fu Song . 2021. Taking care of the discretization problem: A comprehensive study of the discretization problem and a black-box adversarial attack in discrete integer domain . IEEE Transactions on Dependable and Secure Computing ( 2021 ). Lei Bu, Zhe Zhao, Yuchao Duan, and Fu Song. 2021. Taking care of the discretization problem: A comprehensive study of the discretization problem and a black-box adversarial attack in discrete integer domain. IEEE Transactions on Dependable and Secure Computing (2021).
2. Nicholas Carlini and David Wagner . 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . IEEE , 39--57. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). IEEE, 39--57.
3. ImageNet: A large-scale hierarchical image database
4. Boosting Adversarial Attacks with Momentum
5. Logan Engstrom , Brandon Tran , Dimitris Tsipras , Ludwig Schmidt , and Aleksander Madry . 2019 . Exploring the landscape of spatial robustness . In International Conference on Machine Learning. PMLR , 1802--1811. Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2019. Exploring the landscape of spatial robustness. In International Conference on Machine Learning. PMLR, 1802--1811.