From: Secure machine learning against adversarial samples at test time
Attack
FGSM
C&W
BIM
DeepFool
Original
11%
9%
4%
44%
Adversarial training (ART)
98%
99%
Robust classifier