Research Article
Detection Mechanisms of One-Pixel Attack
| Notations | Meaning |
| | Output labels in a DNN model | | The original label | | The target label of a one-pixel attack | | The function that applies a trigger to an image | | The original image | | The modified image A pixel of and represents a pixel of | | and are the and coordinates of the pixel, respectively, and is the color channel | | A trigger of an image | | The loss function measuring classification error | | An element of the candidate solution | | Maximum iteration numbers |
|
|