Research Article
From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples
Figure 8
The impact of different detectors on the detection results AUC (in %). The detector is trained on CW and evaluated on six attacks using SVHN. The perturbation sets to = 5.5.