From: Secure machine learning against adversarial samples at test time
Attack
FGSM
C&W
BIM
DeepFool
Original
16%
46%
8%
13%
Robust classifier
47%
78%
80%
36%