Research Article

Boosting Adversarial Attacks on Neural Networks with Better Optimizer

Table 3

Comparison of combined methods and original methods on attack success rates (%) against adversarially trained networks under the single-model setting.

AttackInc-v3ens3Inc-v3ens4Incres-v2ensAverage

SI-NI-TI54.752.334.447.1
SI-AI-TI (ours)56.354.439.450.0

SI-NI-DI39.537.219.332.0
SI-AI-DI (ours)50.851.527.743.3

SI-NI-TI-DI62.359.341.754.4
SI-AI-TI-DI (ours)72.669.853.065.1

The adversarial examples are generated on the ensemble of Inc-v3, Inc-v4, Incres-v2, and Res-101.