18. Reference
• Adversarial examples in the physical world (ICLR2017 Workshop)
• Ian Speech on CS231n
• DeepFool: a simple and accurate method to fool deep neural
networks (CVPR2016) The idea in this work is close to the orginal
idea. Loop until the predicted label change.
• Learning with a strong adversary (rejected by ICLR2016?) Apply the
spirit of GAN to optimization.
• Explaining and Harnessing Adversarial Examples (ICLR2015) Fast
Gradient Sign Method
• Exploring the space of adversarial images IJCNN