Research Article

From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples

Table 1

Detection performance of AUC (in %) on CIFAR-10 using original samples. Detector is trained and evaluated on the specified adversarial examples. For example, 92.6 below represents that the detector is trained on BIM, whereas evaluated on adversarial examples generated by FGSM.

DatasetDetectorFGSMBIMPGDJSMACWDF

CIFAR-10FGSM99.165.563.755.648.950.4
BIM92.691.691.773.552.254.7
PGD97.598.398.582.350.250.6
JSMA81.575.680.488.548.951.3
CW51.849.850.950.649.552.6
DF48.951.750.049.351.753.4