Abstract: Highlights•Adversarial example detection based on prediction confidence and attention mechanism.•A dual-stream framework is designed to detect both slight and large perturbations.•Spatial filters and attention mechanisms are utilized to enhance detection performance.•Extensive experiments have demonstrated the effectiveness of our method.
Loading