TPR & TNR by input augmentation (adv_a=i_FGSM, LPs=1, y/y'=y)
Notations
- App_i: Approach i
- Input_Aug: Input Augmentation
Implementation details
- 5 perturbed inputs are generated per benign input
- Input augmentation approach1 - append noise ~Uniform(lower_bound=-0.1, uppper_bound=0.1)
- Input augmentation approach2 - append noise ~Normal(mean=0, std=0.1)
|S| | |S1|/|S2| | |P1| | |P2| | TNR | TPR | Input_Aug | h |
---|---|---|---|---|---|---|---|
500 | 227/273 | 70.850 (9.358) | 121.430 (15.163) | 64.0 (4.3)% | 34.5 (21.7)% | None | 1 |
3000 (500+2500) | 1362/1638 | 289.090 (24.717) | 644.110 (51.828) | 68.0 (3.5)% | 17.5 (12.0)% | App_1 | 1 |
3000 (500+2500) | 1362/1638 | 365.170 (40.151) | 742.320 (93.065) | 68.3 (3.6)% | 14.8 (10.5)% | App_2 | 1 |
1500 | 674/826 | 162.900 (24.819) | 223.570 (38.956) | 79.7 (4.3)% | 65.2 (16.1)% | None | 1 |
9000 (1500+7500) | 4044/4956 | 574.650 (82.479) | 1090.800 (186.220) | 83.7 (3.6)% | 52.4 (17.2)% | App_1 | 1 |
9000 (1500+7500) | 4044/4956 | 682.920 (102.169) | 1378.340 (216.134) | 84.8 (3.4)% | 45.9 (15.8)% | App_2 | 1 |
3000 | 1364/1636 | 432.980 (93.588) | 738.560 (175.844) | 68.8 (6.5)% | 98.2 (3)% | None | 1 |
18000 (3000+15000) | 8185/9815 | 1226.650 (331.550) | 3299.600 (682.530) | 74.5 (5.8)% | 92.7 (6.7)% | App_1 | 1 |
18000 (3000+15000) | 8185/9815 | 1548.330 (359.290) | 3975.600 (833.274) | 74.7 (5.5)% | 89.2 (8.3)% | App_2 | 1 |
500 | 227/273 | 99.480 (21.718) | 141.360 (29.135) | 59.1 (9.2)% | 43.2 (21.9)% | None | 2 |
3000 (500+2500) | 1362/1638 | 272.770 (63.876) | 469.120 (152.296) | 69.3 (7.3)% | 28.2 (16.0)% | App_1 | 2 |
3000 (500+2500) | 1362/1638 | 338.890 (97.934) | 584.250 (181.626) | 68.0 (8.8)% | 28.2 (14.9)% | App_2 | 2 |
1500 | 674/826 | 200.250 (52.630) | 262.800 (58.982) | 77.7 (5.8)% | 79.9 (19.8)% | None | 2 |
9000 (1500+7500) | 4044/4956 | 524.450 (161.528) | 914.390 (239.864) | 82.9 (5.3)% | 64.7 (22.9)% | App_1 | 2 |
9000 (1500+7500) | 4044/4956 | 651.990 (205.734) | 1189.720 (363.669) | 82.9 (5.8)% | 58.7 (19.8)% | App_2 | 2 |
3000 | 1364/1636 | 463.520 (100.624) | 674.400 (170.379) | 71.4 (6.6)% | 99.1 (2.1)% | None | 2 |
18000 (3000+15000) | 8185/9815 | 1205.820 (332.480) | 2549.280 (701.297) | 76.0 (6.3)% | 95.6 (6.9)% | App_1 | 2 |
18000 (3000+15000) | 8185/9815 | 1427.990 (383.569) | 3360.290 (995.905) | 76.0 (7.4)% | 91.7 (8.3)% | App_2 | 2 |