Research Article

Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems

Figure 6

Comparison of confidences between the clean image and the adversarial examples by the improved PGD method. We take the confidence as the horizontal axis and the number as the vertical axis. (a) Confidence distribution of detection results except for “dog” on the clean image in Figures 4(a). (b) Confidence distribution of detection results on the adversarial example for nontargeted attacks. (c) Confidence distribution of detection results which are all detected as “dog” on the adversarial example for targeted attacks.
(a)
(b)
(c)