Research Article

Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems

Figure 4

Four clean images for experiments and their corresponding adversarial examples generated by the improved PGD method for nontargeted attacks. (a–d) All images shot from cameras installed in a tram driver’s cab, and each of them consists of multiple objects such as cars, pedestrians, and traffic lights.
(a)
(b)
(c)
(d)
(e)
(f)
(g)
(h)