Research Article

[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation

Table 1

Top-1 accuracy (%) under I-FGSM attack (ϵ = 0.007, n = 100).

Target modelWithout defenseWith (11, 100, 100) bilateral filterWith size 3 median blurProposed method
ClearAttackClearAttackClearAttackClearAttack

AlexNet52.20.437.031.348.530.453.450.7
VGG-1670.80.346.842.561.451.066.663.3
VGG-1971.30.348.042.963.053.669.465.1
Inception69.88.457.754.264.153.570.467.7
ResNet-5073.50.061.355.969.864.575.573.3
ResNet-15276.80.265.361.373.667.878.277.3