AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing Flows

Neural Information Processing Systems 

Deep learning classifiers are susceptible to well-crafted, imperceptible variations of their inputs, known as adversarial attacks.