Towards Deep Learning Models Resistant to Adversarial Attacks, Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, Adrian Vladu, 2017International Conference on Learning Representations (ICLR'18)DOI: 10.48550/arXiv.1706.06083 - Introduces Projected Gradient Descent (PGD) as a strong, widely recognized adversarial attack and a benchmark for robustness.