From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples
Table 4
Comparison of AUC (%) under various evaluation setups. Our method HLFD takes the last two layers of representation and the mid-high and high-frequency regions as input. The norm of perturbation of MNIST is 2.8, the norm of T-ImageNet is 22, and the other three datasets are all = 5.5.