Research Article
Towards Attack to MemGuard with Nonlocal-Means Method
Figure 2
(a) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset location. (b) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset Texas100. (c) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset CH-MNIST.
(a) |
(b) |
(c) |