Research Article

Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems

Figure 8

Comparison of confidences between the clean image and the adversarial examples by the improved C&W method. We take the confidence as the horizontal axis and the number as the vertical axis. (a) Confidence distribution of detection results on the clean image in Figure 4(a). (b) Confidence distribution of detection results on the adversarial example for nontargeted attacks. (c) Confidence distribution of detection results which are all detected as “dog” on the adversarial example for targeted attacks.
(a)
(b)
(c)