Table 14 Defense effectiveness of combined methods on CIFAR-10.
From: Universal attention guided adversarial defense using feature pyramid and non-local mechanisms
Attack algorithm | Ours | Ours+ALP | Ours+TRADES | Ours+GridMask | Ours+AdaAD | Ours+AdaAD_IAD |
---|---|---|---|---|---|---|
Clean | 86.8% | 86.0% | 89.7% | 84.1% | 84.7% | 87.2% |
FGSM | 53.3% | 53.4% | 30.6% | 45.8% | 66.5% | 59.9% |
I-FGSM | 61.8% | 61.7% | 13.8% | 57.6% | 72.1% | 59.7% |
PGD | 66.7% | 65.8% | 12.7% | 62.5% | 73.4% | 66.9% |
MI-FGSM | 58.9% | 59.0% | 18.5% | 54.8% | 71.1% | 58.5% |
\(\hbox {DI}^2\)-FGSM | 62.1% | 61.9% | 13.7% | 59.8% | 71.8% | 61.4% |
TI-FGSM | 54.6% | 55.0% | 34.9% | 55.8% | 67.8% | 63.4% |
Deepfool | 85.9% | 85.2% | 83.2% | 82.8% | 83.7% | 86.3% |
C&W | 86.7% | 85.6% | 86.6% | 83.3% | 84.1% | 86.6% |
Square | 70.5% | 69.5% | 56.9% | 67.7% | 73.1% | 73.1% |