Cycle-Consistent Adversarial GAN: The Integration of Adversarial Attack and Defense
Table 3
Classification accuracy rates of adversarial examples crafted by FGSM, BIM, PGD, and CycleAdvGAN. FGSM (attack with ) and FGSM (defense with ) means that we train the CycleAdvGAN with the adversarial examples crafted by FGSM.