Skip to main content
Advertisement
Browse Subject Areas
?

Click through the PLOS taxonomy to find articles in your field.

For more information about PLOS Subject Areas, click here.

< Back to Article

Table 1.

Problems in robustness assessment of other literatures.

More »

Table 1 Expand

Table 2.

Norms used in robustness assessment in other literatures.

More »

Table 2 Expand

Fig 1.

Example of false adversarial sample.

We present an example of a false adversarial sample (right) and its respective original sample (left). The false adversarial sample is built with few total perturbations (i.e., low L1 and L2) but an unrecognisable final image (false adversarial sample). This results from the non-constrained spatial distribution of perturbations which is prevented if low L0 or L is used. This hypothetical attack has a L2 of merely 356, well below the maximum L2 for the One-Pixel (L0 ≤ 1) Attack (765).

More »

Fig 1 Expand

Table 3.

Description of various parameters of different adversarial attacks.

More »

Table 3 Expand

Table 4.

Adversarial accuracy results for Few-Pixel (L0) and Threshold (L) attacks with DE and CMA-ES.

More »

Table 4 Expand

Table 5.

Adversarial accuracy results for L0 and L attacks over 100 random samples.

More »

Table 5 Expand

Fig 2.

Adversarial accuracy per th for L0 attack.

More »

Fig 2 Expand

Fig 3.

Adversarial accuracy per th for L attack.

More »

Fig 3 Expand

Table 6.

Area under the curve (AUC) for both Few-Pixel (L0) and Threshold (L) black-box attacks.

More »

Table 6 Expand

Table 7.

Adversarial accuracy of the proposed L0 and L black-box attacks used in the robustness assessment compared with other methods from the literature.

More »

Table 7 Expand

Fig 4.

Adversarial accuracy from Table 5 across classes.

The two diagrams at left and right are respectively L0 and L attacks. The top diagrams used th = 10 while the bottom ones used th = 1.

More »

Fig 4 Expand

Fig 5.

Transferability of adversarial samples.

Accuracy of adversarial samples when transferring from the a given source model (row) to a target model (column) for both L black-box Attacks (left) and L0 black-box Attacks (right). The source of the adversarial samples is on the y-axis with the target model on the x-axis. The adversarial samples were acquired from 100 original images attacked with th varying mostly from one to ten. The maximum value of th is set to 127.

More »

Fig 5 Expand

Fig 6.

Distribution of adversarial samples.

Distribution of adversarial samples found on DenseNet (left) and ResNet (right) using th = 10 with both few-pixel (L0) and threshold (L) Attacks.

More »

Fig 6 Expand