Research Article
[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation
Table 2
Top-1 accuracy (%) under FGSM, DeepFool, and C&W attacks.
| Target model | Clear | FGSM | DeepFool | C&W | No defense | Our method | No defense | Our method | No defense | Our method | No defense | Proposed method |
| AlexNet | 58.5 | 57.0 | 20.0 | 55.0 | 0.0 | 56.5 | 0.0 | 54.0 | VGG-16 | 76.0 | 71.0 | 20.0 | 61.5 | 0.0 | 61.0 | 0.0 | 65.0 | VGG-19 | 76.0 | 71.5 | 20.0 | 63.0 | 0.0 | 66.0 | 0.0 | 71.5 | Inception | 71.0 | 73.5 | 31.5 | 71.0 | 0.0 | 72.5 | 0.0 | 71.0 | ResNet-50 | 79.0 | 82.0 | 26.5 | 78.0 | 0.0 | 79.5 | 0.0 | 81.0 | ResNet-152 | 79.0 | 80.0 | 37.0 | 78.5 | 0.0 | 76.5 | 0.0 | 79.0 |
|
|