Model Robustness

The robustness evaluation of DL models against adversarial attacks

The following figures show the average attack success rate on LeNet-1, LeNet-5, ResNet20 and VGG-16, which are trained from different DL frameworks.

LeNet-1

LeNet-5

ResNet-20

VGG-16

The robustness indicator of DL models

Based on the success rates against attacks shown in above figures, we compute the model robustness indicator under different DL frameworks, using the Equation (1) and (2) in the paper. The details are as follows. Note that, for each model, we mark the maximum and minimum values of robustness indicator as bold italic black and bold red, respectively.