Research Article
[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation
Figure 8
Transferability test (blue: our defense method and orange: randomization defense). The AlexNet model was attacked with EOT-PGD under different defenses to generate an adversarial example. Then, the adversarial examples were classified by using the AlexNet and ResNet-101 (solid and dashed lines represent the AlexNet and the ResNet-101, respectively).