Table 15 Robustness against adversarial patches.
From: Universal attention guided adversarial defense using feature pyramid and non-local mechanisms
Attack algorithm | baseline | baseline_at | FPAS_at | ANL_at |
|---|---|---|---|---|
Clean | 58.8% | 49.7% | 53.9% | 58.5% |
FGSM | 56.8% | 47.7% | 52.3% | 56.0% |
I-FGSM | 33.0% | 37.0% | 41.0% | 41.7% |
PGD | 37.3% | 39.2% | 44.8% | 44.8% |
MI-FGSM | 32.4% | 35.8% | 40.8% | 41.0% |
\(\hbox {DI}^2\)-FGSM | 32.9% | 35.0% | 40.7% | 40.4% |
TI-FGSM | 30.3% | 33.1% | 40.1% | 40.5% |
Deepfool | 58.3% | 49.4% | 53.2% | 57.2% |
C&W | 58.4% | 50.0% | 53.7% | 58.0% |
Square | 48.7% | 45.1% | 50.6% | 53.5% |