Research Article

From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples

Figure 7

Impact of the representations of different layers on the detection rate AUC (in %). The detector is trained on normal samples and adversarial samples generated by FGSM.