“…Adversarial attacks were discovered in the seminal paper by Szegedy et al [47], and have since been extensively explored in the image domain [17,29,52,44,24,58,20,55,5,2,29,43,36,8,26], natural language processing [14,6,22], and reinforcement learning [16], to name just a few. In this paper, we focus on universal attacks for geometric data, hence this section covers relevant prior work addressing the two aspects.…”