AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing Flows

Neural Information Processing Systems 

In this regard, the design of stronger adversarial attacks plays a crucial role in understanding the nature of possible real-world threats.