R. Labaca-Castro, Biggio, B., and Rodosek, G. Dreo,
“Poster: Attacking Malware Classifiers by Crafting Gradient-Attacks That Preserve Functionality”, in
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA, 2019, pp. 2565–2567.