affiliation not provided to SSRN
Text Classification, adversarial attack, score-based adversarial attack, hard-to-attack examples.