Research Article
Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples
Table 4
Performance of the single statistical detector (%).
| Positive examples | FGSM | R-FGSM | BIM | UAP | Overall | TPR | 99.9 | 100 | 100 | 98.3 | 99.6 |
| Negative examples | DeepFool | CW_UT | CW_T | Legitimate | Overall | FPR | 0.6 | 0.6 | 0.6 | 0.7 | 0.6 |
|
|