1. Intriguing properties of neural networks;Szegedy;ICLR,2014
2. Adversarial examples are not bugs, they are features;Ilyas;NeurIPS,2019
3. Certified adversarial robustness via randomized smoothing;Cohen,2019
4. Denoised smoothing: A provable defense for pretrained classifiers;Salman;NeurIPS,2020