Constructing Unrestricted Adversarial Examples with Generative Models

Yang Song, Rui Shu, Nate Kushman, Stefano Ermon

Neural Information Processing Systems 

To mitigate the threat of adversarial examples, a large number of methods have been developed.