Research Article

Cycle-Consistent Adversarial GAN: The Integration of Adversarial Attack and Defense

Table 7

The cosine similarity of four successive perturbations in FGSM, BIM, PGD, and CycleAdvGAN when attacking ResNet-18 model. The results are averaged over 10000 images.

 FGSM [8]BIM [9]PGD [24]CycleAdvGAN

Cosine similarity0.30720.350.330.44