Research Article

Boosting Adversarial Attacks on Neural Networks with Better Optimizer

Figure 3

Attack success rates (%) of adversarial examples generated for Inc-v3 with AI-FGM, applied to Inc-v3 (white-box), Inc-v4 (black-box and normally trained), and Inc-v3ens4 (black-box and adversarially trained) with and in the range of . (a) Inc-v3. (b) Inc-v4. (c) Inc-v3ens4.
(a)
(b)
(c)