Skip to main content
. Author manuscript; available in PMC: 2021 Dec 22.
Published in final edited form as: Phys Med Biol. 2020 Dec 22;65(24):245037. doi: 10.1088/1361-6560/abc812

Table 2.

Average and standard deviation of percentage of successfully attacked samples computed over 10 models generated in the 10-fold cross validation.

SAN/Ntrain ± std (%)
10 mAs 50 mAs 100 mAs 200 mAs 500 mAs
Random attacks Training 49.7±4.9 24.8±4.2 11.2±4.1 3.0±2.1 0.9±0.4
Testing 52.3±2.9 29.1±5.0 17.4±4.3 9.6±2.7 4.5±1.3
Optimized attacks Training 59.2±6.3 34.7±6.3 23.4±6.6 13.6±6.5 6.6±4.2
Testing 61.8±5.5 44.4±6.3 34.3±7.5 25.4±6.4 19.3±5.1