Yeah, many ways. Besides what the article describes there are at least 5-10 known attacks at the moment.
By “attack” the authors mean figuring out ways to trick the network into classifying things incorrectly. For example, you might attack a network that recognizes faces by determining certain inputs that still are recognizable as faces to a human, but not to the network.
A practical example of this is getting ads in banned ad categories (drugs, sex, etc.) around google or facebooks ad filters