Research Article

Detection Mechanisms of One-Pixel Attack

Table 2

Network structure of VGG-16.

Conv2d layer (, , )
Conv2d layer (, , )
 Max pooling layer (, )
Conv2d layer (, , )
Conv2d layer (, , )
 Max pooling layer (, )
Conv2d layer (, , )
Conv2d layer (, , )
Conv2d layer (, , )
 Max pooling layer (, )
Conv2d layer (, , )
Conv2d layer (, , )
Conv2d layer (, , )
 Max pooling layer (, )
Conv2d layer (, , )
Conv2d layer (, , )
Conv2d layer (, , )
 Max pooling layer (, )
Flatten layer
Fully connected ()
Fully connected ()
Softmax classifier