Research Article
Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes
Table 2
Results of the attack against ECOC for CIFAR-10 classification.
| Parameters | Proposed (ECOC) | C&W (ECOC) | C&W (one-hot) | ASR (%) | PSNR | ASR (%) | PSNR | ASR (%) | PSNR |
| (1e − 4, 5, 100, 0) | 69.3 | 38.59 | 53.6 | 39.71 | 92.5 | 40.03 | (1e − 4, 5, 500, 0) | 88.0 | 38.52 | 62.3 | 39.94 | 100 | 40.27 | (1e − 4, 10, 200, 0) | 90.6 | 37.84 | 79 | 37.32 | 100 | 40.18 | (1e − 4, 10, 500, 0) | 95.0 | 38.39 | 82.6 | 37.55 | 100 | 40.30 | (1e − 1, 10, 2000, 0) | 98.6 | 38.41 | 92.6 | 36.97 | 100 | 39.99 |
|
|
Reported parameters indicate, respectively (start point, number of steps of binary search, max iterations, confidence).
|