Research Article

[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation

Figure 6

The comparison of our work with JPG compression [18] and randomization [19] (ResNet-50 top-1 accuracy under I-FGSM attack).