From: Smooth adversarial examples
Bilateral filter
Adv. training
Psuc
\({\overline {D}}\)
FGSM
0.77
5.13
0.04
10.20
I-FGSM
0.82
5.12
0.02
10.10
PGD2
1.00
5.14
0.12
10.26
C&W
4.75
10.21
qPGD2
0.95
0.01
10.17
sC&W
0.68
2.91
4.63