1. Ensemble Adversarial Training: Attacks In addition, Defenses;Tramer;arXiv,2018
2. Intriguing properties of neural networks;Szegedy;arXiv,2013
3. The MNIST Database of Handwritten Digitshttp://yann.lecun.com/exdb/mnist/
4. Adversarial Examples for Edge Detection: They Exist, and They Transfer;Cosgrove;arXiv,2019
5. Why Do Adversarial Attacks;Demontis,2019