1. Intriguing properties of neural networks;Szegedy,2014
2. Increasing-Margin Adversarial (IMA) training to improve adversarial robustness of neural networks
3. Robustness of classifiers: from adversarial to random noise;Fawzi;Advances in neural information processing systems,2016
4. Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets;Balaji;arXiv preprint arXiv:1910.08051,2019
5. Attacks which do not kill training make adversarial learning stronger;Zhang,2020