Fig. 7From: Secure machine learning against adversarial samples at test timeReduction in the attack success rate (%) as a function of perturbation injected by the FGSM and BIM attacks, respectivelyBack to article page