Practical Black-Box Attacks against Machine Learning Systems using Adversarial Examples, Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami, 2017Proceedings of the 2017 ACM Asia Conference on Computer and Communications Security (ASIACCS) (Association for Computing Machinery, Inc.)DOI: 10.1145/3052973.3053009 - Details black-box adversarial attacks using transferability and surrogate models, a primary strategy for attacking ensembles when model details are unknown.
Ensemble Adversarial Training: Attacks and Defenses, Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, Patrick McDaniel, 2017arXiv preprint arXiv:1705.07204DOI: 10.48550/arXiv.1705.07204 - Presents ensemble adversarial training and discusses white-box attack strategies against ensembles, including optimizing combined outputs and targeting multiple members simultaneously.