Research Article
Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples
Table 9
Performance of ResGN optimized by FGSM adversarial examples with strength
.
| Training set | Testing set |
| FGSM | FGSM | | | | | 80.6 | 86.3 | 89.9 | 93.6 | R-FGSM | | | | | 78.8 | 81.4 | 87.2 | 92.3 | BIM | | | | | 79.3 | 90.6 | 86.8 | 91.2 | UAP | DeepFool | CW_UT | CW_T | Legitimate | Average | 90.4 | 90.6 | 91.7 | 90.4 | 98.1 | 87.6 |
|
|