1. Intriguing properties of neural networks;Szegedy,2014
2. Towards deep learning models resistant to adversarial attacks;Madry,2018
3. Breaking certified defenses: Semantic adversarial examples with spoofed robustness certificates;Ghiasi,2020
4. Wasserstein adversarial examples via projected sinkhorn iterations;Wong
5. Adversarial Examples in the Physical World