Skip to main content

Table 4 GPBEAM attacks BEAM-related models of different multi-layer architectures (ε is a parameter to ensure the perturbations are small. In this table, the maximum value of \(\epsilon\) is 0.5, which is much smaller than 50, the maximum value of elements in BEAMs. Adding gaussian noise (Gn) with a mean of 0 and a standard deviation of 0.5 is as the baseline attacking for comparison.)

From: Perturbing BEAMs: EEG adversarial attack to deep learning models for epilepsy diagnosing

Architecture

Maxpool

Temporal convolution

LSTM

Mixed LSTM

\(\epsilon\)

Acc

SR

\({\mathrm{DL}}_{B}\)

Acc

SR

\({\mathrm{DL}}_{B}\)

Acc

SR

\({\mathrm{DL}}_{B}\)

Acc

SR

\({\mathrm{DL}}_{B}\)

\(0\)

0.92

-

-

0.92

-

-

0.93

-

-

0.94

-

-

\(0.1\)

0.42

0.50

0.10

0.34

0.57

0.10

0.68

0.24

0.11

0.72

0.21

0.10

\(0.3\)

0.17

0.75

0.30

0.15

0.77

0.21

0.56

0.36

0.32

0.62

0.31

0.31

\(0.5\)

0.12

0.80

0.50

0.09

0.82

0.51

0.53

0.39

0.53

0.58

0.35

0.52

Gn (Baseline)

0.84

0.12

0.69

0.81

0.16

0.69

0.84

0.13

0.69

0.79

0.17

0.69