- Yucheng Zhao
- Zhiding Zhou
- Airu Liu
Accuracy Comparison (Top-1 / Top-5 %):
| Dataset | ResNet‑34 | DenseNet‑121 |
|---|---|---|
| Clean | 76.00 / 94.20 | 74.80 / 93.60 |
| FGSM | 3.60 / 21.40 | 46.00 / 76.20 |
| PGD | 0.00 / 6.60 | 61.80 / 89.20 |
| Patch | 20.00 / 50.40 | 70.20 / 91.40 |
Figure 1: accuracy_line_plot for top1 and top5
Max L∞ raw distance: 0.020000025629997253
FGSM Adversarial Top-1 Accuracy: 3.60%
FGSM Adversarial Top-5 Accuracy: 21.40%
Max L∞ raw distance (PGD): 0.009160018526017666
PGD Adversarial Top-1 Accuracy: 0.00%
PGD Adversarial Top-5 Accuracy: 6.80%
Targeted Patch Attack Top-1 Accuracy: 20.00%
Targeted Patch Attack Top-5 Accuracy: 50.20%
Figure 4: Task4 Targeted Patch Attack
[1] https://chat.openai.com, 2023. Accessed: May 2025.
[2] Explaining and harnessing adversarial examples.
[3] Transferability in machine learning: from phenomena to black-box attacks using adversarial samples.
[4] Intriguing properties of neural networks.

