Skip to main content
. Author manuscript; available in PMC: 2021 Dec 22.
Published in final edited form as: Phys Med Biol. 2020 Dec 22;65(24):245037. doi: 10.1088/1361-6560/abc812

Table 3.

Percentage of samples attacked successfully at 100 mAs level for different network architectures.

SAN/Ntrain (%)
Training Testing

100 mAs Random attacks Original 11.2±4.1 17.4±4.3

Scenario 1 Batch-Norm 10.6±3.7 15.7±4.4

Scenario 2 Drop-out (0.1) 13.4±4.8 27.4±5.1
Drop-out (0.2) 10.2±4.0 20.0±4.5

Scenario 3 Deeper 12.0±5.2 23.2±5.6
Shallower 9.1±3.7 17.9±4.2
Wider 9.6±3.9 15.8±3.6
Narrower 12.7±4.7 28.5±4.6

Scenario 4 Five-class 26.2±6.9 86.5±15.3