基于双重引导的目标对抗攻击方法
孙月,张兴兰

Targeted adversarial attack method based on dual guidance
Yue SUN,Xinglan ZHANG
表 3 不同攻击方法在SVNH数据集上的目标攻击成功率
Tab.3 Targeted ASRs of various attack methods on SVHN dataset
攻击方法tASR/%
VGG16ResNet18Inv3DenseNetWideResNet平均
MIM99.9197.3494.7895.7596.2896.04
Auto-PGD100.0091.1283.7286.9387.5487.33
DIM99.8191.7486.1488.6289.0688.89
TIM99.1883.6476.8279.7480.3280.13
SIM99.9194.9992.0693.3393.3693.44
VMI-FGSM99.9895.5193.3294.1794.4594.36
DO-M-DI299.8692.8287.3489.7890.7490.17
DeCowA99.1689.7783.8686.1386.6886.61
IDAA87.9783.5280.7880.3981.0581.44
LOGIT99.9796.8093.0894.6095.4994.99
POTRIP99.6992.1988.5688.4789.5289.69
AdvGAN97.5997.0094.7595.3095.9195.74
本研究方法97.9797.7997.0797.7897.6997.58