Research Article
[Retracted] Adversarial Attacks Defense Method Based on Multiple Filtering and Image Rotation
Table 4
The classification accuracy (our defense).
| Attack | Classify | AlexNet (%) | VGG-19 (%) | Inception (%) | ResNet-50 (%) |
| AlexNet | 9 | 63.5 | 63.5 | 65 | VGG-19 | 40.5 | 13.5 | 63 | 63.5 | Inception | 34.5 | 46.5 | 18 | 57 | ResNet-50 | 30.5 | 35.5 | 60.5 | 20 |
|
|