L. Demetrio, Biggio, B., Lagorio, G., Roli, F., and Armando, A.,
“Functionality-Preserving Black-Box Optimization of Adversarial Windows Malware”,
IEEE Transactions on Information Forensics and Security, vol. 16, pp. 3469-3478, 2021.
A. Emanuele Cinà, Vascon, S., Demontis, A., Biggio, B., Roli, F., and Pelillo, M.,
“The Hammer and the Nut: Is Bilevel Optimization Really Needed to Poison Linear Classifiers?”, in
International Joint Conference on Neural Networks, (IJCNN) 2021, Shenzhen, China, 2021, pp. 1–8.