Skip to main content

Table 3 Success probability and average L2 distortion \({\overline {D}}\) of attacks on variants of InceptionV3 under transferability

From: Smooth adversarial examples

 

Bilateral filter

Adv. training

 

Psuc

\({\overline {D}}\)

Psuc

\({\overline {D}}\)

FGSM

0.77

5.13

0.04

10.20

I-FGSM

0.82

5.12

0.02

10.10

PGD2

1.00

5.14

0.12

10.26

C&W

0.82

4.75

0.02

10.21

qPGD2

0.95

5.13

0.01

10.17

sC&W

0.68

2.91

0.01

4.63