Loading paper
The best defense is a good offense: Countering black box attacks by predicting slightly wrong labels | Tomesphere