Table 1.
Problems in robustness assessment of other literatures.
Table 2.
Norms used in robustness assessment in other literatures.
Fig 1.
Example of false adversarial sample.
We present an example of a false adversarial sample (right) and its respective original sample (left). The false adversarial sample is built with few total perturbations (i.e., low L1 and L2) but an unrecognisable final image (false adversarial sample). This results from the non-constrained spatial distribution of perturbations which is prevented if low L0 or L∞ is used. This hypothetical attack has a L2 of merely 356, well below the maximum L2 for the One-Pixel (L0 ≤ 1) Attack (765).
Table 3.
Description of various parameters of different adversarial attacks.
Table 4.
Adversarial accuracy results for Few-Pixel (L0) and Threshold (L∞) attacks with DE and CMA-ES.
Table 5.
Adversarial accuracy results for L0 and L∞ attacks over 100 random samples.
Fig 2.
Adversarial accuracy per th for L0 attack.
Fig 3.
Adversarial accuracy per th for L∞ attack.
Table 6.
Area under the curve (AUC) for both Few-Pixel (L0) and Threshold (L∞) black-box attacks.
Table 7.
Adversarial accuracy of the proposed L0 and L∞ black-box attacks used in the robustness assessment compared with other methods from the literature.
Fig 4.
Adversarial accuracy from Table 5 across classes.
The two diagrams at left and right are respectively L0 and L∞ attacks. The top diagrams used th = 10 while the bottom ones used th = 1.
Fig 5.
Transferability of adversarial samples.
Accuracy of adversarial samples when transferring from the a given source model (row) to a target model (column) for both L∞ black-box Attacks (left) and L0 black-box Attacks (right). The source of the adversarial samples is on the y-axis with the target model on the x-axis. The adversarial samples were acquired from 100 original images attacked with th varying mostly from one to ten. The maximum value of th is set to 127.
Fig 6.
Distribution of adversarial samples.
Distribution of adversarial samples found on DenseNet (left) and ResNet (right) using th = 10 with both few-pixel (L0) and threshold (L∞) Attacks.