Effectiveness of various attacks in both the digital and physical domain. ASRs are averaged across all patches correctly classified before the attack, on the top 10 highest energy patches of each image, and after majority voting on the top 10 patches.
| Attack Method | ASR Digital(%) | PSNR (dB) | ASR Printed All Patches(%) | ASR Printed Top 10 Patches(%) | PSNR (dB) | ASR Printed Majority Voting(%) |
|---|---|---|---|---|---|---|
| ifgsm | 100% | 36.14 | 27.20% | 15.5% | 28.89 | 10% |
| ifgsm (eot) | 96.39% | 20.08 | 75.33% | 33.5% | 17.25 | 25% |
| ifgsm (eOT+P&S) | 100% | 13.12 | 85.79% | 69.0% | 11.89 | 70% |
| cw | 100% | 33.86 | 22.82% | 14.0% | 25.53 | 10% |
| cw (eot) | 96.67% | 19.52 | 64.94% | 28.0% | 16.96 | 20% |
| cw (eot+p&s) | 100% | 12.19 | 79.92% | 56.5% | 11.18 | 65% |
| Attack Method | ASR Digital(%) | PSNR (dB) | ASR Printed All Patches(%) | ASR Printed Top 10 Patches(%) | PSNR (dB) | ASR Printed Majority Voting(%) |
|---|---|---|---|---|---|---|