Table 9 Attention guidance effects of FPAS on CIFAR-10.

From: Universal attention guided adversarial defense using feature pyramid and non-local mechanisms

Attack algorithm

\(IoU_{avg}^{baseline}\)

\(IoU_{avg}^{FPAS}\)

\(Num\_Rate\)

FGSM

67.4%

68.9%

54.7%

I-FGSM

76.0%

77.0%

55.0%

PGD

78.2%

79.0%

56.2%

MI-FGSM

74.6%

75.6%

55.0%

\(\hbox {DI}^2\)-FGSM

77.8%

78.8%

56.3%

TI-FGSM

74.0%

72.9%

47.8%

Deepfool

86.2%

89.4%

77.1%

C&W

78.8%

92.4%

83.3%

Square

74.9%

75.5%

53.3%

Mean value

76.4%

78.8%

59.9%