模型

攻击方法

Inc-v3

Inc-v4

IncRes-v2

Res-101

Adv-Inc-v3

IncRes-v2-ens

平均值

Inc-v3

I-FGSM

99.9*

21.8

16.1

16.5

13.6

5.6

28.9

AF-R-I-FGSM

99.9*

54.2

40.3

33.4

19.2

8.7

42.6

MI-FGSM

99.9*

42.1

36.8

37.4

22.1

9.5

41.3

AF-MI-FGSM

99.9*

58.2

51.1

49.3

26.6

12.8

49.7

AF-R-MI-FGSM

99.9*

70.8

61.6

58.5

32.8

18.2

56.9

Inc-v4

I-FGSM

19.9

99.8*

14.9

17.2

12.6

5.2

28.2

AF-R-I-FGSM

47.6

99.7*

37.3

32.2

18.4

8.4

40.6

MI-FGSM

44.6

99.8*

38.3

39.6

22.2

10.8

42.5

AF-MI-FGSM

60.2

99.7

52.1

51.1

26.3

14.1

50.6

AF-R-MI-FGSM

70.1

99.4*

64.1

61.2

31.9

19.2

57.6

IncRes-v2

I-FGSM

17.9

19.3

98.8*

16.2

14.5

6.9

28.9

AF-R-I-FGSM

44.2

48.7

98.5*

31.9

21.6

13.5

43.1

MI-FGSM

45.1

43.1

98.2*

39.6

26.4

15.1

44.6

AF-MI-FGSM

54.3

54.8

98.4

46.3

31.1

21.8

51.1

AF-R-MI-FGSM

66.3

66.9

97.7*

56.1

37.8

30.4

59.2

Res-101

I-FGSM

10.4

13.8

10.3

99.5*

12.3

5.3

25.3

AF-R-I-FGSM

30.2

37.1

27.2

99.1*

17.5

8.3

36.6

MI-FGSM

26.6

31.7

22.7

99.7*

20.8

8.1

34.9

AF-MI-FGSM

32.3

38.9

32.2

98.8

21.6

9.1

38.8

AF-R-MI-FGSM

48.8

53.2

44.5

98.4*

25.2

13.5

47.2