Research Article
[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation
Table 1
Top-1 accuracy (%) under I-FGSM attack (ϵ = 0.007, n = 100).
| Target model | Without defense | With (11, 100, 100) bilateral filter | With size 3 median blur | Proposed method | Clear | Attack | Clear | Attack | Clear | Attack | Clear | Attack |
| AlexNet | 52.2 | 0.4 | 37.0 | 31.3 | 48.5 | 30.4 | 53.4 | 50.7 | VGG-16 | 70.8 | 0.3 | 46.8 | 42.5 | 61.4 | 51.0 | 66.6 | 63.3 | VGG-19 | 71.3 | 0.3 | 48.0 | 42.9 | 63.0 | 53.6 | 69.4 | 65.1 | Inception | 69.8 | 8.4 | 57.7 | 54.2 | 64.1 | 53.5 | 70.4 | 67.7 | ResNet-50 | 73.5 | 0.0 | 61.3 | 55.9 | 69.8 | 64.5 | 75.5 | 73.3 | ResNet-152 | 76.8 | 0.2 | 65.3 | 61.3 | 73.6 | 67.8 | 78.2 | 77.3 |
|
|