Research Article
FAPA: Transferable Adversarial Attacks Based on Foreground Attention
Table 2
Attack success rate of the typical algorithm in the CNN model (%).
| Method | Inc-v3 | Inc-v4 | IncRes-v2 | Mean |
| FGSM | 20.78 | 18.80 | 16.38 | 18.65 | BIM | 17.88 | 14.77 | 12.40 | 15.02 | MI | 39.65 | 37.43 | 32.17 | 36.42 | DI | 32.78 | 31.75 | 26.40 | 30.31 | TI | 23.27 | 23.60 | 15.28 | 20.72 | SIM | 30.55 | 27.63 | 24.17 | 27.45 | SGM | 38.42 | 34.00 | 27.25 | 33.22 | IR | 17.65 | 15.83 | 12.08 | 15.19 | TAP | 29.58 | 26.10 | 20.67 | 25.45 | ATA | 3.25 | 2.53 | 2.03 | 2.60 | SE | 18.40 | 16.47 | 12.33 | 15.73 |
|
|