I. Goodfellow, J. Shlens, and C. Szegedy, Explaining and harnessing adversarial examples, International Conference on Learning Representations, 2015.

C. Szegedy, W. Zaremba, I. Sutskever, and J. Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks, 2013.

C. Simon-gabriel, Y. Ollivier, B. Schölkopf, L. Bottou, and D. Lopez-paz, Adversarial vulnerability of neural networks increases with input dimension, 2018.

M. Hein and M. Andriushchenko, Formal guarantees on the robustness of a classifier against adversarial manipulation, Advances in Neural Information Processing Systems, pp.2266-2276, 2017.

H. Drucker and Y. Le-cun, Improving generalization performance using double backpropagation, IEEE Transactions on Neural Networks, vol.3, issue.6, pp.991-997, 1992.
DOI : 10.1109/72.165600

S. Hochreiter and J. Schmidhuber, Simplifying neural nets by discovering flat minima, Advances in neural information processing systems, pp.529-536, 1995.

N. Papernot, P. Mcdaniel, X. Wu, S. Jha, and A. Swami, Distillation as a defense to adversarial perturbations against deep neural networks, 2016 IEEE Symposium on Security and Privacy (SP), pp.582-597, 2016.
DOI : 10.1109/sp.2016.41

URL : http://arxiv.org/pdf/1511.04508