Fig. 7
From: Secure machine learning against adversarial samples at test time

Reduction in the attack success rate (%) as a function of perturbation injected by the FGSM and BIM attacks, respectively
From: Secure machine learning against adversarial samples at test time
Reduction in the attack success rate (%) as a function of perturbation injected by the FGSM and BIM attacks, respectively