1. Virtual Adversarial Training: A Regularization Method for Supervised and Semi-Supervised Learning
2. Unlabeled data improves adversarial robustness;carmon;Advances in neural information processing systems,2019
3. Large-Scale Machine Learning with Stochastic Gradient Descent
4. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples;athalye;International Conference on Machine Learning,2018
5. Adversarially robust generalization just requires more unlabeled data;zhai;Advances in neural information processing systems,2019