Skip to main content

Table 2 Success probability and average L2 distortion \({\overline {D}}\) when attacking networks adversarially trained against FGSM

From: Smooth adversarial examples

 

MNIST - C4

ImageNet - InceptionV3

 

Psuc

\({\overline {D}}\)

Psuc

\({\overline {D}}\)

FGSM

0.15

4.53

0.06

6.40

I-FGSM

1.00

3.48

0.97

29.94

PGD2

1.00

2.52

1.00

3.89

C&W

0.93

3.03

0.95

6.43

qPGD2

0.99

2.94

0.69

7.86

sC&W

0.99

2.39

0.75

6.22