Research Article

Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems

Figure 7

Detection results of Faster R-CNN using the improved C&W method. (a) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (b) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (c–f) Detection results on the adversarial examples for targeted attacks generated from Figures 4(a)4(d), respectively.
(a)
(b)
(c)
(d)
(e)
(f)