1. M. Sharif et al., arXiv:1801.00349 (2017).
2. A. Huang et al., arXiv:1801.02950 (2018).
3. R. Huang, B. Xu, D. Schuurmans, and C. Szepesvári, arXiv:1511.03034 (2015).
4. A. Madry et al., “Towards deep learning models resistant to adversarial attacks,” in ICML 2017 Workshop (2017).
5. The Theory of Max-Min, with Applications