Research Article

[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation

Table 3

The classification accuracy (randomization defense).

AttackClassify
AlexNet (%)VGG-19 (%)Inception (%)ResNet-50 (%)

AlexNet967.58
VGG-198.59.57.58.5
Inception119.5129.5
ResNet-5016.515.51920