Fig. 5From: Secure machine learning against adversarial samples at test timeAdversarial image generation speed under the BIM attack. Image generation speeds under the BIM attack. Note that CPU has a much faster adversarial image generation speed than K40C, TitanV, and both K40C and TitanVBack to article page