Research Article

From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples

Figure 9

Ablation studies on the representations of different layers and frequency bands. The colous represent different frequency bands. The detector is trained on normal samples and adversarial samples generated by CW. The detection rate AUC (in %) is evaluated by adversarial samples generated by DeepFool.