Research Article
Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems
Figure 5
Detection results of Faster R-CNN using the improved PGD method. (a) Detection result on the clean image in Figure 4(a). (b) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (c) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (d) Detection result on the adversarial example for targeted attacks. (e–g) Detection results on the adversarial examples for targeted attacks generated from Figures 4(b)–4(d), respectively.
(a) |
(b) |
(c) |
(d) |
(e) |
(f) |
(g) |