Research Article

Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems

Figure 5

Detection results of Faster R-CNN using the improved PGD method. (a) Detection result on the clean image in Figure 4(a). (b) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (c) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (d) Detection result on the adversarial example for targeted attacks. (e–g) Detection results on the adversarial examples for targeted attacks generated from Figures 4(b)4(d), respectively.
(a)
(b)
(c)
(d)
(e)
(f)
(g)