Research Article
Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes
Table 1
Results of the attack against ECOC for GTSRB classification.
| Parameters | Proposed (ECOC) | C&W (ECOC) | C&W (one-hot) | ASR (%) | PSNR | ASR (%) | PSNR | ASR (%) | PSNR |
| (1e − 4, 5, 100, 0) | 40.3 | 41.43 | 7.0 | 48.80 | 25.5 | 46.82 | (1e − 4, 5, 200, 0) | 45.6 | 41.58 | 8.6 | 48.48 | 37.5 | 45.73 | (1e − 4, 5, 500, 0) | 53.3 | 41.65 | 11.3 | 48.03 | 47.5 | 46.07 | (1e − 2, 5, 500, 0) | 70.6 | 39.85 | 20.0 | 43.94 | 61 | 43.41 | (1e − 1, 10, 2000, 0) | 93.3 | 38.97 | 42.3 | 39.20 | 81.5 | 42.51 |
|
|
Reported parameters indicate, respectively (start point, number of steps of binary search, max iterations, and confidence).
|