deep neural networks have been found vulnerable re-cently. A kind of
well-designed inputs, which called adver-sarial examples, can lead the networks
to make incorrectpredictions. Depending on the different scenarios, goalsand
capabilities, the difficulties of the attacks are different.