1. Adversarial perturbations against deep neural networks for malware classification;grosse,2016
2. Is bert really robust? natural language attack on text classification and entailment;jin,2019
3. The Limitations of Deep Learning in Adversarial Settings
4. Adversarial camera stickers: A physical camera-based attack on deep learning systems;li;International Conference on Machine Learning,2019
5. Robustness to adversarial perturbations in learning from incomplete data;najafi;Advances in neural information processing systems,2019