Automated Discovery of Adaptive Attacks on Adversarial Defenses

Neural Information Processing Systems 

The issue of adversarial attacks (Szegedy et al., 2014; Goodfellow et al., 2015), i.e., crafting small input perturbations that lead to mispredictions, is an important problem with a large body of recent work.