Research Article
From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples
Table 1
Detection performance of AUC (in %) on CIFAR-10 using original samples. Detector is trained and evaluated on the specified adversarial examples. For example, 92.6 below represents that the detector is trained on BIM, whereas evaluated on adversarial examples generated by FGSM.
|