Research Article
Boosting Adversarial Attacks on Neural Networks with Better Optimizer
Figure 3
Attack success rates (%) of adversarial examples generated for Inc-v3 with AI-FGM, applied to Inc-v3 (white-box), Inc-v4 (black-box and normally trained), and Inc-v3ens4 (black-box and adversarially trained) with and in the range of . (a) Inc-v3. (b) Inc-v4. (c) Inc-v3ens4.
(a) |
(b) |
(c) |