Table 5.
Robustness evaluation under different PGD attack strengths (ϵ).
| ϵ | Baseline CNN | XceptionNet | Ours |
|---|---|---|---|
| 0.0 | 68.3 | 71.1 | 98.2 |
| 0.01 | 42.7 | 48.9 | 85.3 |
| 0.02 | 28.4 | 31.5 | 78.6 |
| 0.04 | 15.6 | 19.7 | 64.9 |
Metrics are overall classification accuracy (%). The bold values indicate the best performance during a comparison.