We gratefully acknowledge support from
the Simons Foundation and member institutions.

Haidar Khan is qualified to endorse.

Thwarting finite difference adversarial attacks with output randomization

Haidar Khan: Is registered as an author of this paper.
Can endorse for cs.AI, cs.LG. (why?)

Daniel Park, Azer Khan and Bülent Yener are not registered as owners of this paper. (why?)