Shi, et al.. Generative Adversarial Networks for Black-box API Attacks with Limited Training Data. 25 Jan. 2019.