Skip to main content
Fig. 3 | Cybersecurity

Fig. 3

From: Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks

Fig. 3

The attack against Defense Approaches. The fooling rate (%) on 1k ImageNet val. The adversarial examples at \(\epsilon \le\) 16. The fooling rate of the original SE and TR methods combined with PGD, MIM, DIM and TIM, and the fooling rate of these methods combined with our method. The source model is Mixer-B/16. The target models are a ResNet50_FastAT, b ResNet50_FreeAT, c AdvEfficientNet-b0 and d ResNet152_denoise. Our method can further overcome adversarial defense methods such as FastAT, FreeAT, adversarial training and denoise

Back to article page