Existing neural network-based autonomous systems are shown to be vulnerable against adversarial attacks, therefore sophisticated evaluation of their robustness is great importance. However, evaluating the under worst-case scenarios based on known attacks not comprehensive, mention that some them even rarely occur in real world. Also, distribution safety-critical data usually multimodal, while m...