Research Article

FAPA: Transferable Adversarial Attacks Based on Foreground Attention

Table 2

Attack success rate of the typical algorithm in the CNN model (%).

MethodInc-v3Inc-v4IncRes-v2Mean

FGSM20.7818.8016.3818.65
BIM17.8814.7712.4015.02
MI39.6537.4332.1736.42
DI32.7831.7526.4030.31
TI23.2723.6015.2820.72
SIM30.5527.6324.1727.45
SGM38.4234.0027.2533.22
IR17.6515.8312.0815.19
TAP29.5826.1020.6725.45
ATA3.252.532.032.60
SE18.4016.4712.3315.73