Research Article
Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples
Figure 2
An overview of proposed complete defense framework. The statistical and minor alteration detectors filter out adversarial examples and the ResGN cleans the adversarial examples. Then, the cleaned examples and legitimate examples are classified by the adversarially trained targeted network.