Table 9 Attention guidance effects of FPAS on CIFAR-10.
From: Universal attention guided adversarial defense using feature pyramid and non-local mechanisms
Attack algorithm | \(IoU_{avg}^{baseline}\) | \(IoU_{avg}^{FPAS}\) | \(Num\_Rate\) |
---|---|---|---|
FGSM | 67.4% | 68.9% | 54.7% |
I-FGSM | 76.0% | 77.0% | 55.0% |
PGD | 78.2% | 79.0% | 56.2% |
MI-FGSM | 74.6% | 75.6% | 55.0% |
\(\hbox {DI}^2\)-FGSM | 77.8% | 78.8% | 56.3% |
TI-FGSM | 74.0% | 72.9% | 47.8% |
Deepfool | 86.2% | 89.4% | 77.1% |
C&W | 78.8% | 92.4% | 83.3% |
Square | 74.9% | 75.5% | 53.3% |
Mean value | 76.4% | 78.8% | 59.9% |