1. Zeyuan Allen-Zhu and Yuanzhi Li. 2022. Feature Purification: How Adversarial Training Performs Robust Deep Learning. arxiv: 2005.10190 [cs.LG]
2. Anubhav Ashok, Nicholas Rhinehart, Fares Beainy, and Kris M. Kitani. 2018. N2N learning: Network to Network Compression via Policy Gradient Reinforcement Learning. In International Conference on Learning Representations. https://openreview.net/pdf?id=B1hcZZ-AW
3. Miriam Bellver, Xavier Giro-i Nieto, Ferran Marques, and Jordi Torres. 2016. Hierarchical Object Detection with Deep Reinforcement Learning. In Deep Reinforcement Learning Workshop, NIPS.
4. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). Ieee 39--57.
5. Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning. PMLR, 2206--2216.