Research Article

Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples

Table 7

Performance of the minor alteration detector (%).

Operationrirercramax

Threshold0.7470.6820.5740.5640.993
TPRDeepFool91.893.490.891.594.7
CW_T92.394.191.292.494.6
CW_UT92.794.191.392.795.0
Overall92.393.991.192.294.8

FPRLegitimate5.76.15.56.04.7