Research Article

Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples

Table 5

Evaluation for transfer ability of the statistical detector for various attacking strengths.

TrainTest
TPR (%)FPR (%)
Average

98.699.599.699.799.41.7
93.699.099.499.597.91.5
86.197.199.399.595.51.4
80.495.198.299.693.30.6