Fig. 5: Anti-attack tests for ADS based on SRMs.

a Schematic diagram of the hardware-software cooperative anti-attack ADS based on the proposed single-layer SRMs. b Flowchart of real-time classification and decision making for YOLOv9 models combined with SRM arrays. c Sample images of the original traffic dataset with the six attack patterns. d Classification accuracy of YOLOv9 model combined with SRM array, GPU-YOLOv9 model, and YOLOv9 model combined with NSRM array on the BDD100K dataset after six-pattern attacks, where G-P denotes Gray Patches, RGB-P denotes RGB Patches, and R, G, B refers to red, green, and blue, respectively. e PR curves of YOLOv9 model combined with SRM array, GPU-YOLOv9 model, and YOLOv9 model combined with NSRM array on the BDD100K dataset after RGB-patch attacks. Variation of classification accuracy of SRMs-based YOLOv9 model with different f device-to-device variations (different colors correspond to different device states), and different g cycle-to-cycle variations (different colors correspond to state changes of the same device). h Four paradigm scenarios of decision from ADS. i Confusing matrix of four aspects of decision from ADS based on SRMs.