Model | Method | ACC Org (%) | ACC Att (%) | Para comb |
---|
Small CNN [17] | Vanilla | 98.53 | 5.50 | / |
Dropout | 92.43 | 34.98 | (0.7, 0.9) |
Flipover | 98.00 | 49.79 | (0.3, 0.0) |
ResNet18 [4] | Vanilla | 93.63 | 23.00 | / |
Dropout | 93.42 | 23.14 | (0.0, 0.3) |
Flipover | 92.37 | 40.99 | (0.3, 0.0) |
- Note: ACC Org stands for the accuracy on the original test set; ACC Att for the accuracy under adversarial attack; Para Comb for the optimal combination of training and test rates