Research Article
Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples
Table 7
Performance of the minor alteration detector (%).
| Operation | ri | re | rc | ra | max |
| Threshold | 0.747 | 0.682 | 0.574 | 0.564 | 0.993 | TPR | DeepFool | 91.8 | 93.4 | 90.8 | 91.5 | 94.7 | CW_T | 92.3 | 94.1 | 91.2 | 92.4 | 94.6 | CW_UT | 92.7 | 94.1 | 91.3 | 92.7 | 95.0 | Overall | 92.3 | 93.9 | 91.1 | 92.2 | 94.8 |
| FPR | Legitimate | 5.7 | 6.1 | 5.5 | 6.0 | 4.7 |
|
|