1. Cifar-10 (canadian institute for advanced research);krizhevsky,0
2. Is bert really robust? natural language attack on text classification and entailment;jin,2019
3. Adversarial perturbations against deep neural networks for malware classification;grosse,2016
4. Adversarial camera stickers: A physical camera-based attack on deep learning systems;li;International Conference on Machine Learning,2019