Skip to main content
. Author manuscript; available in PMC: 2021 Feb 28.
Published in final edited form as: Neurocomputing (Amst). 2019 Oct 31;379:370–378. doi: 10.1016/j.neucom.2019.10.085

Figure 1:

Figure 1:

The illustration of the effect of adversarial attack. (a) Sample 1 (19 year-old). (b) Sample 2 (80 year-old). (c) Sample 1 with random noise. (d) Sample 1 with adversarial perturbation. The difference among (a), (c) and (d) appears imperceptible to human eye.