Research Article
Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems
Figure 7
Detection results of Faster R-CNN using the improved C&W method. (a) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (b) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (c–f) Detection results on the adversarial examples for targeted attacks generated from Figures 4(a)–4(d), respectively.
| (a) |
| (b) |
| (c) |
| (d) |
| (e) |
| (f) |