Add a small, carefully chosen perturbation to an image and a state-of-the-art classifier sees a school bus instead of a panda. Adversarial examples are the longest-running unresolved problem in machine-learning security and increasingly relevant to deployed systems.