Research Article

Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes

Table 1

Results of the attack against ECOC for GTSRB classification.

ParametersProposed (ECOC)C&W (ECOC)C&W (one-hot)
ASR (%)PSNRASR (%)PSNRASR (%)PSNR

(1e − 4, 5, 100, 0)40.341.437.048.8025.546.82
(1e − 4, 5, 200, 0)45.641.588.648.4837.545.73
(1e − 4, 5, 500, 0)53.341.6511.348.0347.546.07
(1e − 2, 5, 500, 0)70.639.8520.043.946143.41
(1e − 1, 10, 2000, 0)93.338.9742.339.2081.542.51

Reported parameters indicate, respectively (start point, number of steps of binary search, max iterations, and confidence).