Skip to main content

Table 4 Evaluation adversarial robust accuracy (lower is better, \(\downarrow\)) on defense models

From: DTA: distribution transform-based attack for query-limited scenario

Method

Adv-Inc-v3

Inc-v3\(_{ens3}\)

Inc-v3\(_{ens4}\)

IncRes-v2\(_{ens}\)

Clean

94.80

93.20

91.30

97.40

Bandits

86.15

87.5

88.16

92.69

Rays

87.01

82.91

83.03

91.66

TA

89.61

90.32

86.94

92.63

CGBA

91.34

92.43

88.22

96.25

Ours

79.03

79.4

79.98

83.39

  1. The bold results are the best
  2. We first report the clean accuracy of the selected 1000 images, and the following results come from the generated adversarial examples by each attack method