* The Adversarial class now remembers the model output for the best adversarial so far. For deterministic models this is the same as `fmodel.predictions(adversarial.image)`, but it can be useful for non-deterministic models. Note that very close to the decision boundary even otherwise deterministic models can become stochastic because of non-deterministic floating point operations such as `reduce_sum`. In addtion to the new `output` attribute, there is also a new `adversarial_class` attribute for convience; it just takes the argmax of the output.
* new [ADefAttack](https://foolbox.readthedocs.io/en/latest/modules/attacks/gradient.html#foolbox.attacks.ADefAttack) thanks to EvgeniaAR
* new [NewtonFoolAttack](https://foolbox.readthedocs.io/en/latest/modules/attacks/gradient.html#foolbox.attacks.NewtonFoolAttack) thanks to bveliqi
* new FAQ section in the docs: https://foolbox.readthedocs.io/en/latest/user/faq.html