Research Article

Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples

Table 11

The success rates of FGSM and BIM attacking the Inception-v3 and complete defense framework (%).

AttackFGSMBIM

Targeted networkInception-v3Complete defenseInception-v3Complete defense
Success rate73.928.910013.7