基于双重引导的目标对抗攻击方法
|
|
孙月,张兴兰
|
Targeted adversarial attack method based on dual guidance
|
|
Yue SUN,Xinglan ZHANG
|
|
| 表 3 不同攻击方法在SVNH数据集上的目标攻击成功率 |
| Tab.3 Targeted ASRs of various attack methods on SVHN dataset |
|
| 攻击方法 | tASR/% | | VGG16 | ResNet18 | Inv3 | DenseNet | WideResNet | 平均 | | MIM | 99.91 | 97.34 | 94.78 | 95.75 | 96.28 | 96.04 | | Auto-PGD | 100.00 | 91.12 | 83.72 | 86.93 | 87.54 | 87.33 | | DIM | 99.81 | 91.74 | 86.14 | 88.62 | 89.06 | 88.89 | | TIM | 99.18 | 83.64 | 76.82 | 79.74 | 80.32 | 80.13 | | SIM | 99.91 | 94.99 | 92.06 | 93.33 | 93.36 | 93.44 | | VMI-FGSM | 99.98 | 95.51 | 93.32 | 94.17 | 94.45 | 94.36 | | DO-M-DI2 | 99.86 | 92.82 | 87.34 | 89.78 | 90.74 | 90.17 | | DeCowA | 99.16 | 89.77 | 83.86 | 86.13 | 86.68 | 86.61 | | IDAA | 87.97 | 83.52 | 80.78 | 80.39 | 81.05 | 81.44 | | LOGIT | 99.97 | 96.80 | 93.08 | 94.60 | 95.49 | 94.99 | | POTRIP | 99.69 | 92.19 | 88.56 | 88.47 | 89.52 | 89.69 | | AdvGAN | 97.59 | 97.00 | 94.75 | 95.30 | 95.91 | 95.74 | | 本研究方法 | 97.97 | 97.79 | 97.07 | 97.78 | 97.69 | 97.58 |
|
|
|