Skip to main content

Table 3 Top 1 classification accuracy under the graffiti attack and art attacks scenario (%)

From: Defense against adversarial attacks in traffic sign images identification based on 5G

Models Graffiti Art
5M 0° 43.73%/89.78% 36.23%/90.21%
5M 15° 41.27%/87.65% 56.73%/91.56%
5M 30° 28.98%/86.42% 57.49%/93.41%
10M 0° 46.96%/85.74% 23.58%/92.37%
10M 15° 10.62%/86.93% 28.43%/93.20%
10M 30° 36.42%/86.29% 20.81%/90.79%
20M 0° 38.96%/88.04% 31.65%/89.67%
30M 0° 40.29%/89.45% 24.68%/91.35%