Skip to main content

Table 2 Top-1 classification accuracy under the poster-printing attack scenario (M means meter, º means angel. The former is the accuracy of the target model, the latter is the accuracy of the defense model)

From: Defense against adversarial attacks in traffic sign images identification based on 5G

Setting I-FGSM C&W Deepfool JSMA
5M 0° 13.73%/82.91% 5.91%/90.21% 22.41%/82.61% 15.71%/90.66%
5M 15° 11.27%/81.75% 6.06%/84.82% 23.04%/81.25% 23.22%/89.34%
5M 30° 12.98%/85.96% 10.31%/88.18% 30.96%/87.15% 26.65%/88.52%
10M 0° 12.96%/87.65% 9.58%/87.52% 25.63%/88.64% 18.96%/90.72%
10M 15° 10.62%/89.51% 8.69%/82.65% 27.12%/89.61% 23.41%/89.26%
10M 30° 6.09%/85.63% 13.37%/85.31% 29.59%/90.13% 25.67%/89.17%
20M 0° 16.64%/87.69% 14.24%/84.93% 20.76%/87.69% 21.19%/88.93%
30M 0° 27.21%/90.39% 12.17%/87.45% 19.36%/88.42% 21.39%/89.93%