1. [1] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” arXiv preprint arXiv:1312.6199, 2013.
2. [2] A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial examples in the physical world,” ILCR-W, 2017.
3. [3] K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, F. Tramer, A. Prakash, T. Kohno, and D. Song, “Physical adversarial examples for object detectors,” WOOT, 2018.
4. [4] C. Sitawarin, A.N. Bhagoji, A. Mosenia, M. Chiang, and P. Mittal, “Darts: Deceiving autonomous cars with toxic signs,” arXiv preprint arXiv:1802.06430, 2018.
5. [5] A. Boloor, X. He, C. Gill, Y. Vorobeychik, and X. Zhang, “Simple physical adversarial examples against end-to-end autonomous driving models,” arXiv preprint arXiv:1903.05157, 2019.