Reachable Sets of Classifiers & Regression Models: (Non-)Robustness Analysis and Robust Training. STA: Adversarial Attacks on Siamese Trackers. Learning To Characterize Adversarial Subspaces. Playing the Game of Universal Adversarial Perturbations. Utilizing Network Properties to Detect Erroneous Inputs. Robustness Verification of Tree-based Models. Generalizing Universal Adversarial Attacks Beyond Additive Perturbations. Detecting Anomalous Inputs to DNN Classifiers By Joint Statistical Testing at the Layers. Query-Efficient Black-box Adversarial Examples (superceded). Adversarial Attack on DL-based Massive MIMO CSI Feedback. FDA3 : Federated Defense Against Adversarial Attacks for Cloud-Based IIoT Applications. Robust Machine Comprehension Models via Adversarial Training. (99%), Mitigating the Impact of Adversarial Attacks in Very Deep Networks. A Data-driven Adversarial Examples Recognition Framework via Adversarial Feature Genome. Graph Interpolating Activation Improves Both Natural and Robust Accuracies in Data-Efficient Deep Learning. Penetrating RF Fingerprinting-based Authentication with a Generative Adversarial Attack. When Bots Take Over the Stock Market: Evasion Attacks Against Algorithmic Traders. Detecting Adversarial Perturbations with Saliency. On Configurable Defense against Adversarial Example Attacks. Adversarial Robustness Against the Union of Multiple Perturbation Models. Automatic Generation of Adversarial Examples for Interpreting Malware Classifiers. Detecting Audio Attacks on ASR Systems with Dropout Uncertainty. Daedalus: Breaking Non-Maximum Suppression in Object Detection via Adversarial Examples. Adversarial Robustness: Softmax versus Openmax. Adversarial Examples for Electrocardiograms. ECGadv: Generating Adversarial Electrocardiogram to Misguide Arrhythmia Classification System. Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter Effect. Audio Adversarial Examples for Robust Hybrid CTC/Attention Speech Recognition. Sequential Attacks on Agents for Long-Term Adversarial Goals. Defending against Contagious Attacks on a Network with Resource Reallocation. RayS: A Ray Searching Method for Hard-label Adversarial Attack. ReabsNet: Detecting and Revising Adversarial Examples. Feature Purification: How Adversarial Training Performs Robust Deep Learning. Undersensitivity in Neural Reading Comprehension. Defending Adversarial Attacks by Correcting logits. Certifying Neural Network Robustness to Random Input Noise from Samples. Adversarial Learning in the Cyber Security Domain. A Kernelized Manifold Mapping to Diminish the Effect of Adversarial Perturbations. Detection of Face Recognition Adversarial Attacks. Adversarial Examples against the iCub Humanoid. Adversarial point perturbations on 3D objects. Identifying Audio Adversarial Examples via Anomalous Pattern Detection. Learning Transferable Adversarial Examples via Ghost Networks. New CleverHans Feature: Better Adversarial Robustness Evaluations with Attack Bundling. Adversarial and Clean Data Are Not Twins. Temporal Sparse Adversarial Attack on Gait Recognition. Adversarial Transferability in Wearable Sensor Systems. Color and Edge-Aware Adversarial Image Perturbations. Gradient Band-based Adversarial Training for Generalized Attack Immunity of A3C Path Finding. Passport-aware Normalization for Deep Model Protection. Extensions and limitations of randomized smoothing for robustness guarantees. Targeted Attention Attack on Deep Learning Models in Road Sign Recognition. MediaEval 2019: Concealed FGSM Perturbations for Privacy Preservation. Understanding Catastrophic Overfitting in Single-step Adversarial Training. LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud-based Deep Networks. Certified Robustness of Graph Neural Networks against Adversarial Structural Perturbation. Integer Programming-based Error-Correcting Output Code Design for Robust Classification. The Adversarial Machine Learning Conundrum: Can The Insecurity of ML Become The Achilles' Heel of Cognitive Networks? ZO-AdaMM: Zeroth-Order Adaptive Momentum Method for Black-Box Optimization. Adversarial Example Generation with Syntactically Controlled Paraphrase Networks. The Search for Sparse, Robust Neural Networks. Customizing an Adversarial Example Generator with Class-Conditional GANs. Adversarial Attacks for Optical Flow-Based Action Recognition Classifiers. Siamese Generative Adversarial Privatizer for Biometric Data. Attacking Automatic Video Analysis Algorithms: A Case Study of Google Cloud Video Intelligence API. ATRO: Adversarial Training with a Rejection Option. Building robust classifiers through generation of confident out of distribution examples. Adversarial Examples Against Automatic Speech Recognition. On Lyapunov exponents and adversarial perturbation. The Taboo Trap: Behavioural Detection of Adversarial Samples. Bypassing Feature Squeezing by Increasing Adversary Strength. Towards Evaluating the Robustness of Neural Networks. Generating Natural Adversarial Hyperspectral examples with a modified Wasserstein GAN. Understanding Object Detection Through An Adversarial Lens. Query-Efficient Black-Box Attack Against Sequence-Based Malware Classifiers. PermuteAttack: Counterfactual Explanation of Machine Learning Credit Scorecards. Detecting Patch Adversarial Attacks with Image Residuals. Practical Fast Gradient Sign Attack against Mammographic Image Classifier. Characterizing the Shape of Activation Space in Deep Neural Networks. Improving Robustness Without Sacrificing Accuracy with Patch Gaussian Augmentation. Random Spiking and Systematic Evaluation of Defenses Against Adversarial Examples. Optimal Attacks on Reinforcement Learning Policies. Universal adversarial examples in speech command classification. Calibrated neighborhood aware confidence measure for deep metric learning. Estimating Principal Components under Adversarial Perturbations. Non-Negative Networks Against Adversarial Attacks. HAWKEYE: Adversarial Example Detector for Deep Neural Networks. Hessian-based Analysis of Large Batch Training and Robustness to Adversaries. Android HIV: A Study of Repackaging Malware for Evading Machine-Learning Detection. Data augmentation using synthetic data for time series classification with deep residual networks. Spatial-aware Online Adversarial Perturbations Against Visual Object Tracking. Fast Gradient Attack on Network Embedding. Adversarially Robust Few-Shot Learning: A Meta-Learning Approach. Adversarial Metric Attack and Defense for Person Re-identification. Efficient Adversarial Attacks for Visual Object Tracking. Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach. Robust Design of Deep Neural Networks against Adversarial Attacks based on Lyapunov Theory. the field of adversarial examples, Hold Tight and Never Let Go: Security of Deep Learning based Automated Lane Centering under Physical-World Attack. Logit Pairing Methods Can Fool Gradient-Based Attacks. Combinatorial Attacks on Binarized Neural Networks. Detecting Adversarial Examples in Learning-Enabled Cyber-Physical Systems using Variational Autoencoder for Regression. Uncertainty-aware Attention Graph Neural Network for Defending Adversarial Attacks. Semidefinite relaxations for certifying robustness to adversarial examples. Generating Label Cohesive and Well-Formed Adversarial Claims. DeepTest: Automated Testing of Deep-Neural-Network-driven Autonomous Cars. PHom-GeM: Persistent Homology for Generative Models. A Survey: Towards a Robust Deep Neural Network in Text Domain. Query-limited Black-box Attacks to Classifiers. advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable Patterns. Role of Spatial Context in Adversarial Robustness for Object Detection. Divide, Denoise, and Defend against Adversarial Attacks. Backdoor Attack with Sample-Specific Triggers. Universal Decision-Based Black-Box Perturbations: Breaking Security-Through-Obscurity Defenses. SentiNet: Detecting Localized Universal Attacks Against Deep Learning Systems. Learning Adversary-Resistant Deep Neural Networks. The only requirement I used for selecting papers for this list is that it is primarily a paper about adversarial examples, or extensively uses adversarial examples. Do Gradient-based Explanations Tell Anything About Adversarial Robustness to Android Malware? SwitchX- Gmin-Gmax Switching for Energy-Efficient and Robust Implementation of Binary Neural Networks on Memristive Xbars. PeerNets: Exploiting Peer Wisdom Against Adversarial Attacks. Beware the Black-Box: on the Robustness of Recent Defenses to Adversarial Examples. Towards A Unified Min-Max Framework for Adversarial Exploration and Robustness. Rethinking Non-idealities in Memristive Crossbars for Adversarial Robustness in Neural Networks. A general framework for defining and optimizing robustness. Deep Neural Network Fingerprinting by Conferrable Adversarial Examples. Using Self-Supervised Learning Can Improve Model Robustness and Uncertainty. Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. Unsupervised Euclidean Distance Attack on Network Embedding. Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-Ranking. Black-box Adversarial Attacks with Limited Queries and Information. On Norm-Agnostic Robustness of Adversarial Training. Maximal Jacobian-based Saliency Map Attack. Combating Linguistic Discrimination with Inflectional Perturbations. Vax-a-Net: Training-time Defence Against Adversarial Patch Attacks. HYDRA: Pruning Adversarially Robust Neural Networks. Latent Adversarial Debiasing: Mitigating Collider Bias in Deep Neural Networks. Attack Graph Convolutional Networks by Adding Fake Nodes. A Self-supervised Approach for Adversarial Robustness. Adversarial Example Generation using Evolutionary Multi-objective Optimization. Controlling Over-generalization and its Effect on Adversarial Examples Generation and Detection. Accelerated Zeroth-Order Momentum Methods from Mini to Minimax Optimization. Investigating Image Applications Based on Spatial-Frequency Transform and Deep Learning Techniques. The Efficacy of SHIELD under Different Threat Models. On the Effectiveness of Interval Bound Propagation for Training Verifiably Robust Models. Adversarial Attack Type I: Cheat Classifiers by Significant Changes. Targeted Nonlinear Adversarial Perturbations in Images and Videos. There are No Bit Parts for Sign Bits in Black-Box Attacks. Large Margin Deep Networks for Classification. A Noise-Sensitivity-Analysis-Based Test Prioritization Technique for Deep Neural Networks. Say What I Want: Towards the Dark Side of Neural Dialogue Models. Explainability and Adversarial Robustness for RNNs. HASP: A High-Performance Adaptive Mobile Security Enhancement Against Malicious Speech Recognition. Attention, Please! Enhancing Recurrent Neural Networks with Sememes. Stochastically Rank-Regularized Tensor Regression Networks. DAPAS : Denoising Autoencoder to Prevent Adversarial attack in Semantic Segmentation. Adversarial Examples - A Complete Characterisation of the Phenomenon. Adversarial Attack on Deep Learning-Based Splice Localization. Countering Inconsistent Labelling by Google's Vision API for Rotated Images. Generating Semantically Valid Adversarial Questions for TableQA. Black-Box Adversarial Attack with Transferable Model-based Embedding. Cronus: Robust and Heterogeneous Collaborative Learning with Black-Box Knowledge Transfer. CG-ATTACK: Modeling the Conditional Distribution of Adversarial Perturbations to Boost Black-Box Attack. Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers. On the Connection Between Adversarial Robustness and Saliency Map Interpretability. FoolHD: Fooling speaker identification by Highly imperceptible adversarial Disturbances. Generalizability vs. Robustness: Adversarial Examples for Medical Imaging. Adversarial T-shirt! Alternative Training via a Soft-Quantization Network with Noisy-Natural Samples Only. FreeLB: Enhanced Adversarial Training for Natural Language Understanding. Towards Robust Image Classification Using Sequential Attention Models. Adversarial Examples Versus Cloud-based Detectors: A Black-box Empirical Study. Simple Black-Box Adversarial Perturbations for Deep Networks. Are Self-Driving Cars Secure? An Efficient and Margin-Approaching Zero-Confidence Adversarial Attack. Inline Detection of DGA Domains Using Side Information. The Robust Manifold Defense: Adversarial Training using Generative Models. Universalization of any adversarial attack using very few test examples. Neural Image Compression and Explanation. Robust Ensemble Model Training via Random Layer Sampling Against Adversarial Attack. Deterministic Gaussian Averaged Neural Networks. DeepConsensus: using the consensus of features from multiple layers to attain robust image classification. Generating End-to-End Adversarial Examples for Malware Classifiers Using Explainability. Precise Tradeoffs in Adversarial Training for Linear Regression. Revisiting Role of Autoencoders in Adversarial Settings. Structured Adversarial Attack: Towards General Implementation and Better Interpretability. Analyzing Federated Learning through an Adversarial Lens. Adversarial Margin Maximization Networks. Deep Detector Health Management under Adversarial Campaigns. Dissecting Deep Networks into an Ensemble of Generative Classifiers for Robust Predictions. Exploring the Space of Adversarial Images. Semantic Equivalent Adversarial Data Augmentation for Visual Question Answering. A Comprehensive Study on the Robustness of 18 Deep Image Classification Models. Entropy Guided Adversarial Model for Weakly Supervised Object Localization. Adversarial Item Promotion: Vulnerabilities at the Core of Top-N Recommenders that Use Images to Address Cold Start. Improve Generalization and Robustness of Neural Networks via Weight Scale Shifting Invariant Regularizations. Stochastic Activation Pruning for Robust Adversarial Defense. Security Evaluation of Pattern Classifiers under Attack. Adversarial training and its variants have become de facto standards for learning robust deep neural networks. 