Szegedy 2013 (imperceptible perturbations)

First adversarial examples for images. Established field. Perturbations that flip predictions.

Advertisement

Goodfellow 2014 (FGSM)

Fast Gradient Sign Method. Efficient adversarial example generation. Also introduced GANs.

Advertisement

Papernot 2016 (transferability)

Adversarial examples transfer across models. Black-box attacks possible.