Intriguing properties of neural networks (2013) Explaining and harnessing adversarial examples (2014) Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples (2016) Towards evaluating the robustness of neural networks (2017) Synthesizing robust adversarial examples (2018)