Explaining and Harnessing Adversarial Examples, Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy, 2015arXiv preprintDOI: 10.48550/arXiv.1412.6572 - Introduces the Fast Gradient Sign Method (FGSM) and is a foundational work for adversarial examples, explicitly defining a white-box threat model for evasion attacks.