Research Article
[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation
Table 3
The classification accuracy (randomization defense).
| Attack | Classify | AlexNet (%) | VGG-19 (%) | Inception (%) | ResNet-50 (%) |
| AlexNet | 9 | 6 | 7.5 | 8 | VGG-19 | 8.5 | 9.5 | 7.5 | 8.5 | Inception | 11 | 9.5 | 12 | 9.5 | ResNet-50 | 16.5 | 15.5 | 19 | 20 |
|
|