Research Article

A Defense Framework for Privacy Risks in Remote Machine Learning Service

Figure 5

Comparing the training/test accuracy of original training data (no perturbation) with adversarial perturbation training data (OPTMARGIN, AdvGAN, and FGSM). (a) OPTIMARGIN perturbation with constraint condition. (b) AdvGAN perturbation with constraint condition. (c) FGSM perturbation with constraint condition.
(a)
(b)
(c)