Research Article
Two Improved Methods of Generating Adversarial Examples against Faster R-CNNs for Tram Environment Perception Systems
Figure 7
Detection results of Faster R-CNN using the improved C&W method. (a) Detection result on the adversarial example for nontargeted attacks with confidence of from 0% to 100% remaining. (b) Detection result on the adversarial example for nontargeted attacks after filtering objects with the confidence of less than 50%. (c–f) Detection results on the adversarial examples for targeted attacks generated from Figures 4(a)–4(d), respectively.
(a) |
(b) |
(c) |
(d) |
(e) |
(f) |