Fig. 4From: Gaussian class-conditional simplex loss for accurate, adversarially robust deep classifier trainingTest accuracy as a function of \(\epsilon\) under gradient-based adversarial attacks, both targeted and untargeted (AT indicates also adversarial training is employed): a– d FGSM attack; e–h PGD attack (5 iterations); i–l TGSM attack (5 iterations); m–p JSMA attack (200 iterations, 1 pixel)Back to article page