QuadAttacK: A Quadratic Programming Approach to Learning Ordered Top-K Adversarial Attacks

Neural Information Processing Systems 

The adversarial vulnerability of Deep Neural Networks (DNNs) has been wellknown and widely concerned, often under the context of learning top-1 attacks (e.g., fooling a DNN to classify a cat image as dog).