Research Article

Boosting Adversarial Attacks on Neural Networks with Better Optimizer

Figure 4

Attack success rates (%) of adversarial examples generated for Inc-v3 with I-FGSM, MI-FGSM, and AI-FGM, applied to Inc-v3 (white-box) and Inc-v4 (black-box) with ranging from 1 to 20. It is noteworthy that the curves of Inc-v3 vs. I-FGSM, Inc-v3 vs. MI-FGSM, and Inc-v3 vs. AI-FGM overlap.