Research Article

Boosting Adversarial Attacks on Neural Networks with Better Optimizer

Table 4

Comparison of SI-AI-TI-DI and SI-NI-TI-DI under the ensemble-model setting.

AttackInc-v3ens3Inc-v3ens4Incres-v2ensAverage

SI-NI-TI-DI95.493.789.592.9
SI-AI-TI-DI (ours)96.296.092.795.0

The adversarial examples are generated on the ensemble of Inc-v3, Inc-v4, Incres-v2, and Res-101.