Research Article

Boosting Adversarial Attacks on Neural Networks with Better Optimizer

Table 2

Attack success rates (%) on adversarially trained networks under the ensemble-model setting.

AttackInc-v3ens3Inc-v3ens4Incres-v2ensAverage

FGSM18.617.39.515.1
I-FGSM20.116.911.416.1
MI-FGSM49.443.225.939.5
NI-FGSM46.741.623.037.1
AI-FGM (ours)56.250.633.046.6

The adversarial examples are generated on the ensemble of Inc-v3, Inc-v4, IncRes-v2, and Res-101.