Table 14 Defense effectiveness of combined methods on CIFAR-10.

From: Universal attention guided adversarial defense using feature pyramid and non-local mechanisms

Attack

algorithm

Ours

Ours+ALP

Ours+TRADES

Ours+GridMask

Ours+AdaAD

Ours+AdaAD_IAD

Clean

86.8%

86.0%

89.7%

84.1%

84.7%

87.2%

FGSM

53.3%

53.4%

30.6%

45.8%

66.5%

59.9%

I-FGSM

61.8%

61.7%

13.8%

57.6%

72.1%

59.7%

PGD

66.7%

65.8%

12.7%

62.5%

73.4%

66.9%

MI-FGSM

58.9%

59.0%

18.5%

54.8%

71.1%

58.5%

\(\hbox {DI}^2\)-FGSM

62.1%

61.9%

13.7%

59.8%

71.8%

61.4%

TI-FGSM

54.6%

55.0%

34.9%

55.8%

67.8%

63.4%

Deepfool

85.9%

85.2%

83.2%

82.8%

83.7%

86.3%

C&W

86.7%

85.6%

86.6%

83.3%

84.1%

86.6%

Square

70.5%

69.5%

56.9%

67.7%

73.1%

73.1%