Table 3

Effectiveness of various attacks in both the digital and physical domain. ASRs are averaged across all patches correctly classified before the attack, on the top 10 highest energy patches of each image, and after majority voting on the top 10 patches.

Attack MethodASR Digital(%)PSNR (dB)ASR Printed All Patches(%)ASR Printed Top 10 Patches(%)PSNR (dB)ASR Printed Majority Voting(%)
ifgsm100%36.1427.20%15.5%28.8910%
ifgsm (eot)96.39%20.0875.33%33.5%17.2525%
ifgsm (eOT+P&S)100%13.1285.79%69.0%11.8970%
cw100%33.8622.82%14.0%25.5310%
cw (eot)96.67%19.5264.94%28.0%16.9620%
cw (eot+p&s)100%12.1979.92%56.5%11.1865%

or Create an Account

Close Modal
Close Modal