1. Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2014, January 14–16). Intriguing Properties of Neural Networks. Proceedings of the International Conference on Learning Representations (ICLR), Banff, AB, Canada.
2. Athalye, A., Carlini, N., and Wagner, D. (2018, January 10–15). Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. Proceedings of the International Conference on Machine Learning, PMLR, Stockholm, Sweden.
3. Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (May, January 30). Towards Deep Learning Models Resistant to Adversarial Attacks. Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada.
4. Zhang, H., Yu, Y., Jiao, J., Xing, E., Ghaoui, L.E., and Jordan, M. (2019, January 9–15). Theoretically Principled Trade-off between Robustness and Accuracy. Proceedings of the 36th International Conference on Machine Learning, PMLR, Long Beach, CA, USA.
5. Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J.C., and Liang, P.S. (2019). Advances in Neural Information Processing Systems, Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, BC, Canada, 8–14 December 2019, Curran Associates, Inc.