Research Article
Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems
Figure 5
Detection results of Faster R-CNN using the improved PGD method. (a) Detection result on the clean image in Figure 4(a). (b) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (c) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (d) Detection result on the adversarial example for targeted attacks. (e–g) Detection results on the adversarial examples for targeted attacks generated from Figures 4(b)–4(d), respectively.
| (a) |
| (b) |
| (c) |
| (d) |
| (e) |
| (f) |
| (g) |