Adversarial Example Rectification on MNIST (test)
99.9FGSM (L∞) AccuracyProposed method (FGSM)
Evaluation Results
| Method | Links | ||||
|---|---|---|---|---|---|
| Proposed method (FGSM)Approach=Re-attack-based rectification, Re-attack method=FGSM2026.01 | 99.9 | 99.6 | 99.9 | 100 | |
| Proposed method (BIM)Approach=Re-attack-based rectification, Re-attack method=BIM2026.01 | 99.8 | 99.6 | 99.9 | 100 | |
| Proposed method (DF)Approach=Re-attack-based rectification, Re-attack method=DF2026.01 | 99.3 | 99.2 | 99.8 | 100 | |
| Previous method (Kao et al.)Approach=XAI-based rectification2026.01 | 88.9 | 94.9 | 90.5 | 97.2 | |
| Denoising autoencoderApproach=Input transformation2026.01 | 50 | 76 | 58.1 | 62.1 | |
| Full-image Gaussian blurApproach=Input transformation2026.01 | 38.9 | 61.6 | 45.9 | 38.9 | |
| Random pixel replacementApproach=Input transformation2026.01 | 28 | 32 | 28 | 26 | |
| JPEG compressionApproach=Input transformation2026.01 | 3.7 | 11.1 | 9.5 | 0 |