Fig. 13

Trade-off between average Correct Prediction Acceptance (CPA) and Incorrect Prediction Rejection (IPR), evaluated by averaging their values over all adversarial attack types across the range of perturbation magnitudes (\(\epsilon\)) employed in the experiment.