Research Article

Towards Attack to MemGuard with Nonlocal-Means Method

Figure 2

(a) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset location. (b) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset Texas100. (c) The inference accuracy changes as the average confidence score distortion increases from 0 to 1 for MemGuard and our attack schemes for the dataset CH-MNIST.
(a)
(b)
(c)