Cortellazzi, J., Quiring, E., Arp, D., Pendlebury, F., Pierazzi, F., & Cavallaro, L. (2025). Intriguing Properties of Adversarial ML Attacks in the Problem Space [Extended Version]. ACM Transactions on Privacy and Security, 28(4), 1–37. https://doi.org/10.1145/3742895