Research Article
Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples
Figure 4
The SPAM feature in eight directions and the final feature are illustrated. The eight directions are expressed as . The difference between the FGSM adversarial example and legitimate example are distinctly observed.