Hosseini H, Xiao B, Poovendran R (2017) Google’s cloud vision API is not robust to noise. In: 16th IEEE international conference on machine learning and applications (ICMLA)
Szegedy C, Zaremba W, Sutskever I et al (2014) Intriguing properties of neural networks. In: International conference on learning representations (ICLR)
Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: Proceedings of the international conference on learning representations (ICLR)
Rozsa A, Rudd EM, Boult TE (2016) Adversarial diversity and hard positive generation. In: IEEE conference on computer vision and pattern recognition (CVPR) workshops
Kurakin A, Goodfellow IJ, Bengio S (2019) Adversarial examples in the physical world. https://arxiv.org/abs/1607.02533v4. Accessed 11 Apr 2019
Narodytska N, Kasiviswanathan S (2017) Simple black-box adversarial attacks on deep neural networks. In: IEEE conference on computer vision and pattern recognition workshops
Bai W, Quan C, Luo Z (2017) Alleviating adversarial attacks via convolutional autoencoder. In: 18th IEEE/ACIS international conference on software engineering, artificial intelligence, networking and parallel/distributed computing (SNPD)
Papernot N, McDaniel P, Jha S et al (2016) The limitations of deep learning in adversarial settings. In: IEEE European symposium on security and privacy (EuroS&P)
Papernot N, McDaniel P, Goodfellow I et al (2017) Practical black-box attacks against deep learning systems using adversarial examples. In: ACM ASIA CCS
Moosavi-Dezfooli SM, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: IEEE conference on computer vision and pattern recognition (CVPR)
Moosavi-Dezfooli SM, Fawzi O, Fawzi A et al (2017) Universal adversarial perturbations. In: IEEE conference on computer vision and pattern recognition (CVPR)
Mopuri KR, Garg U, Babu RV (2019) Fast feature fool: a data independent approach to universal adversarial perturbations. https://arxiv.org/abs/1707.05572v1. Accessed 11 Apr 2019
Sarkar S, Bansal A, Mahbub U et al (2019) UPSET and ANGRI: breaking high performance image classifiers. https://arxiv.org/abs/1707.01159v1. Accessed 11 Apr 2019
Cisse M, Adi Y, Neverova N et al (2019) Houdini: fooling deep structured prediction models. https://arxiv.org/abs/1707.05373v1. Accessed 11 Apr 2019
Khrulkov V, Oseledets I (2019) Art of singular vectors and universal adversarial perturbations. https://arxiv.org/abs/1709.03582v1. Accessed 11 Apr 2019
Moosavi-Dezfool SM, Fawzi A, Fawzi O et al (2019) Analysis of universal adversarial perturbations. https://arxiv.org/abs/1705.09554v1. Accessed 11 Apr 2019
Rauber J, Brendel W, Bethge M (2019) Foolbox v0.8.0: a Python toolbox to benchmark the robustness of machine learning models. https://arxiv.org/abs/1707.04131v1. Accessed 11 Apr 2019