Research Article

A Sparsity-Limitation-Based High-Dimensional Distribution Searching Algorithm for Adversarial Attack

Table 1

Comparison experiments of the four algorithms.

AttackResNet-50VGG-16GoogleNetMobileNet-v2
Success (%)TimeSuccess (%)TimeSuccess (%)TimeSuccess (%)Time

AdvGAN98.2017.32 s95.7216.39 s98.1617.99 s97.7718.32 s
TREMBA99.52437.7 s100.0316.9 s99.85280.2 s100.0144.8 s
ColorFool89.7226.98 h91.2524.50 h85.2929.88 h89.2330.93 h
SparseAdv97.2612.22 s96.3213.58 s99.0214.78 s95.3512.64 s

The four compared algorithms include AdvGAN, TREMBA, ColorFool, and our SparseAdv. There are two performance metrics containing attack successful rate (%) and time of batch (1000) generation.