Skip to main content

Table 2 Top-1 classification accuracy under the poster-printing attack scenario (M means meter, º means angel. The former is the accuracy of the target model, the latter is the accuracy of the defense model)

From: Defense against adversarial attacks in traffic sign images identification based on 5G

Setting

I-FGSM

C&W

Deepfool

JSMA

5M 0°

13.73%/82.91%

5.91%/90.21%

22.41%/82.61%

15.71%/90.66%

5M 15°

11.27%/81.75%

6.06%/84.82%

23.04%/81.25%

23.22%/89.34%

5M 30°

12.98%/85.96%

10.31%/88.18%

30.96%/87.15%

26.65%/88.52%

10M 0°

12.96%/87.65%

9.58%/87.52%

25.63%/88.64%

18.96%/90.72%

10M 15°

10.62%/89.51%

8.69%/82.65%

27.12%/89.61%

23.41%/89.26%

10M 30°

6.09%/85.63%

13.37%/85.31%

29.59%/90.13%

25.67%/89.17%

20M 0°

16.64%/87.69%

14.24%/84.93%

20.76%/87.69%

21.19%/88.93%

30M 0°

27.21%/90.39%

12.17%/87.45%

19.36%/88.42%

21.39%/89.93%