Evading classifiers in discrete domains with provable optimality guarantees

Open in new window