* Official reported data is put in parentheses
Model | Top-1 | Top-5 |
---|---|---|
alexnet | 56.5%(56.6%) | 79.1%(79.1%) |
densenet121 | 74.4%(74.7%) | 92.0%(92.2%) |
densenet169 | 75.6%(76.0%) | 92.8%(93.0%) |
densenet201 | 76.9%(77.2%) | 93.4%(93.6%) |
googlenet | 69.8%(69.8%) | 89.5%(89.5%) |
inception_v3 | 77.2%(77.5%) | 93.5%(93.6%) |
mnasnet | 73.5%(73.5%) | 91.5%(91.5%) |
mobilenet_v2 | 71.9%(71.9%) | 90.3%(90.3%) |
resnet101 | 77.4%(77.4%) | 93.5%(93.6%) |
resnet152 | 78.3%(78.3%) | 94.0%(94.1%) |
resnet50 | 76.1%(76.2%) | 92.9%(92.9%) |
resnext50_32x4d | 77.6%(77.6%) | 93.7%(93.7%) |
shufflenet_V2 | 69.4%(69.4%) | 88.3%(88.3%) |
squeezenet1_0 | 58.1%(58.1%) | 80.4%(80.4%) |
squeezenet1_1 | 58.2%(58.2%) | 80.6%(80.6%) |
vgg16 | 71.6%(71.6%) | 90.4%(90.4%) |
vgg19 | 72.4%(72.4%) | 90.9%(90.9%) |
wide_resnet101_2 | 78.8%(78.8%) | 94.3%(94.3%) |
wide_resnet50_2 | 78.5%(78.5%) | 94.1%(94.1%) |
Model | Layers | Neurons | t=0.0 | t=0.1 | t=0.2 | t=0.3 | t=0.4 | t=0.5 | t=0.6 | t=0.7 | t=0.8 | t=0.9 |
---|---|---|---|---|---|---|---|---|---|---|---|---|
alexnet | 19 | 20456 | 99.8% | 98.7% | 95.0% | 90.9% | 87.7% | 85.4% | 83.6% | 81.9% | 80.3% | 79.0% |
densenet121 | 366 | 94824 | 96.5% | 85.0% | 64.2% | 43.3% | 27.3% | 18.7% | 13.9% | 7.8% | 3.4% | 1.2% |
densenet169 | 510 | 173032 | 94.3% | 78.8% | 62.1% | 42.7% | 25.3% | 15.7% | 10.6% | 5.9% | 2.7% | 0.7% |
densenet201 | 606 | 246504 | 92.8% | 74.5% | 55.3% | 35.8% | 20.6% | 12.4% | 8.0% | 4.6% | 2.1% | 0.5% |
googlenet | 129 | 22808 | 100.0% | 98.9% | 92.7% | 83.0% | 71.8% | 61.1% | 48.7% | 30.5% | 15.1% | 9.4% |
inception_v3 | 189 | 35432 | 100.0% | 96.9% | 84.6% | 74.2% | 64.0% | 54.7% | 45.6% | 28.0% | 10.5% | 3.2% |
mnasnet | 140 | 56152 | 88.8% | 84.3% | 76.6% | 66.7% | 57.3% | 48.6% | 41.9% | 30.1% | 11.1% | 3.8% |
mobilenet_v2 | 140 | 50664 | 99.8% | 96.3% | 82.5% | 69.9% | 59.3% | 51.3% | 45.7% | 32.4% | 10.8% | 4.2% |
resnet101 | 311 | 157288 | 99.3% | 96.2% | 76.6% | 60.2% | 49.3% | 42.7% | 36.3% | 18.1% | 3.6% | 1.9% |
resnet152 | 464 | 226408 | 99.6% | 96.1% | 73.7% | 56.1% | 45.8% | 40.5% | 35.1% | 16.5% | 3.5% | 1.3% |
resnet50 | 158 | 78952 | 99.6% | 97.1% | 81.4% | 67.1% | 55.7% | 48.4% | 40.0% | 17.5% | 5.2% | 3.6% |
resnext50_32x4d | 158 | 101608 | 99.6% | 95.3% | 76.3% | 60.0% | 51.0% | 43.4% | 33.5% | 18.2% | 6.3% | 3.1% |
shufflenet_V2 | 151 | 22834 | 98.4% | 97.8% | 91.7% | 80.0% | 69.4% | 60.7% | 53.4% | 37.9% | 13.4% | 5.2% |
squeezenet1_0 | 56 | 9816 | 100.0% | 94.6% | 77.2% | 55.4% | 26.9% | 17.3% | 12.6% | 11.2% | 10.7% | 10.4% |
squeezenet1_1 | 56 | 9336 | 100.0% | 97.8% | 84.2% | 65.1% | 35.6% | 23.0% | 16.8% | 13.0% | 11.4% | 11.0% |
vgg16 | 37 | 27816 | 100.0% | 95.0% | 81.7% | 72.9% | 67.0% | 64.1% | 62.7% | 62.2% | 62.0% | 61.6% |
vgg19 | 43 | 30376 | 100.0% | 95.0% | 79.8% | 69.5% | 62.8% | 59.0% | 57.4% | 57.0% | 56.7% | 56.4% |
wide_resnet101_2 | 311 | 206056 | 93.0% | 88.6% | 69.8% | 55.0% | 46.0% | 40.1% | 33.3% | 16.0% | 3.0% | 1.1% |
wide_resnet50_2 | 158 | 101608 | 98.7% | 95.0% | 76.8% | 60.8% | 50.0% | 43.2% | 33.6% | 16.5% | 4.3% | 2.1% |
Model | FGSM | BIM | DeepFool | ||||||
---|---|---|---|---|---|---|---|---|---|
Success Rate | Avg Time | Avg Linf Dist | Success Rate | Avg Time | Avg Linf Dist | Success Rate | Avg Time | Avg MSE | |
alexnet | 100.0% | 0.13s | 0.00263500 | 100.0% | 2.91s | 0.00135854 | 100.0% | 0.45s | 0.00000148 |
densenet121 | 100.0% | 0.67s | 0.00610410 | 100.0% | 12.84s | 0.00075278 | 98.0% | 4.25s | 0.00000041 |
densenet169 | 100.0% | 1.12s | 0.00990691 | 100.0% | 18.17s | 0.00088170 | 98.6% | 5.52s | 0.00000044 |
densenet201 | 100.0% | 1.48s | 0.00923320 | 100.0% | 24.49s | 0.00119368 | 98.8% | 6.61s | 0.00000063 |
googlenet | 100.0% | 0.35s | 0.00915289 | 100.0% | 5.87s | 0.00100802 | 99.0% | 1.33s | 0.00000052 |
inception_v3 | 100.0% | 2.14s | 0.04902524 | 100.0% | 16.10s | 0.00189097 | 98.8% | 3.76s | 0.00000101 |
mnasnet | 100.0% | 0.21s | 0.00322124 | 100.0% | 4.72s | 0.00093090 | 99.2% | 1.13s | 0.00000026 |
mobilenet_v2 | 100.0% | 0.24s | 0.00252460 | 100.0% | 4.35s | 0.00060118 | 98.9% | 1.07s | 0.00000024 |
resnet101 | 100.0% | 1.06s | 0.01125438 | 100.0% | 20.31s | 0.00097412 | 99.0% | 5.63s | 0.00000056 |
resnet152 | 100.0% | 1.76s | 0.01530474 | 100.0% | 29.97s | 0.00126433 | 98.0% | 10.27s | 0.00000064 |
resnet50 | 99.9% | 0.57s | 0.01048718 | 100.0% | 10.40s | 0.00089334 | 98.5% | 3.48s | 0.00000053 |
resnext50_32x4d | 100.0% | 1.32s | 0.01523613 | 100.0% | 36.66s | 0.00165673 | 98.0% | 15.22s | 0.00000044 |
shufflenet_V2 | 100.0% | 0.24s | 0.00298274 | 100.0% | 4.73s | 0.00053196 | 97.9% | 1.39s | 0.00000016 |
squeezenet1_0 | 100.0% | 0.13s | 0.00201011 | 100.0% | 2.91s | 0.00079603 | 99.8% | 0.54s | 0.00000042 |
squeezenet1_1 | 100.0% | 0.11s | 0.00161141 | 100.0% | 2.47s | 0.00069972 | 99.5% | 0.50s | 0.00000029 |
vgg16 | 100.0% | 0.77s | 0.00609845 | 100.0% | 15.16s | 0.00164455 | 99.6% | 2.97s | 0.00000044 |
vgg19 | 100.0% | 1.04s | 0.00937630 | 100.0% | 18.14s | 0.00215684 | 99.6% | 3.74s | 0.00000050 |
wide_resnet101_2 | 100.0% | 2.28s | 0.01842678 | 100.0% | 33.85s | 0.00134861 | 98.1% | 11.96s | 0.00000059 |
wide_resnet50_2 | 100.0% | 1.15s | 0.01741704 | 100.0% | 17.65s | 0.00147032 | 98.1% | 5.84s | 0.00000062 |