2019.11.15 note (1)
EXPLAINING AND HARNESSING ADVERSARIAL EXAMPLES
FGSM (Fast Gradient Sign Method)
Adversarial examples in the physical world
Another version:
Towards Deep Learning Models Resistant to Adversarial Attacks
Another version (L2 norm instead of L-inf norm):