Attack success rate by layer with random attack, normal init
conv1                 8 %
layer1.0.bn1          9 %
layer1.0.relu         6 %
layer1.0.conv1       13 %
layer1.0.bn2         11 %
layer1.0.relu_1      14 %
layer1.0.conv2       14 %
layer1.0.add         13 %
layer1.1.bn1         12 %
layer1.1.relu        13 %
layer1.1.conv1       16 %
layer1.1.bn2         17 %
layer1.1.relu_1      13 %
layer1.1.conv2       18 %
layer1.1.add         14 %
layer2.0.bn1         16 %
layer2.0.relu        15 %
layer2.0.shortcut.0  14 %
layer2.0.conv1       19 %
layer2.0.bn2         19 %
layer2.0.relu_1      15 %
layer2.0.conv2       20 %
layer2.0.add         24 %
layer2.1.bn1         22 %
layer2.1.relu        16 %
layer2.1.conv1       29 %
layer2.1.bn2         26 %
layer2.1.relu_1      22 %
layer2.1.conv2       30 %
layer2.1.add         31 %
layer3.0.bn1         30 %
layer3.0.relu        23 %
layer3.0.shortcut.0  26 %
layer3.0.conv1       33 %
layer3.0.bn2         35 %
layer3.0.relu_1      27 %
layer3.0.conv2       35 %
layer3.0.add         39 %
layer3.1.bn1         40 %
layer3.1.relu        33 %
layer3.1.conv1       43 %
layer3.1.bn2         45 %
layer3.1.relu_1      35 %
layer3.1.conv2       47 %
layer3.1.add         47 %
layer4.0.bn1         49 %
layer4.0.relu        39 %
layer4.0.shortcut.0  42 %
layer4.0.conv1       59 %
layer4.0.bn2         63 %
layer4.0.relu_1      39 %
layer4.0.conv2       79 %
layer4.0.add         79 %
layer4.1.bn1         78 %
layer4.1.relu        56 %
layer4.1.conv1       88 %
layer4.1.bn2         88 %
layer4.1.relu_1      81 %
layer4.1.conv2       88 %
layer4.1.add         87 %

Attack success rate by layer with random attack, uniform init
conv1                 7 %
layer1.0.bn1          9 %
layer1.0.relu         6 %
layer1.0.conv1       14 %
layer1.0.bn2         11 %
layer1.0.relu_1      14 %
layer1.0.conv2       15 %
layer1.0.add         13 %
layer1.1.bn1         13 %
layer1.1.relu        13 %
layer1.1.conv1       16 %
layer1.1.bn2         18 %
layer1.1.relu_1      13 %
layer1.1.conv2       18 %
layer1.1.add         15 %
layer2.0.bn1         16 %
layer2.0.relu        14 %
layer2.0.shortcut.0  14 %
layer2.0.conv1       19 %
layer2.0.bn2         20 %
layer2.0.relu_1      16 %
layer2.0.conv2       20 %
layer2.0.add         22 %
layer2.1.bn1         23 %
layer2.1.relu        18 %
layer2.1.conv1       28 %
layer2.1.bn2         27 %
layer2.1.relu_1      22 %
layer2.1.conv2       32 %
layer2.1.add         32 %
layer3.0.bn1         30 %
layer3.0.relu        22 %
layer3.0.shortcut.0  25 %
layer3.0.conv1       32 %
layer3.0.bn2         33 %
layer3.0.relu_1      25 %
layer3.0.conv2       35 %
layer3.0.add         37 %
layer3.1.bn1         38 %
layer3.1.relu        32 %
layer3.1.conv1       42 %
layer3.1.bn2         43 %
layer3.1.relu_1      34 %
layer3.1.conv2       45 %
layer3.1.add         44 %
layer4.0.bn1         48 %
layer4.0.relu        40 %
layer4.0.shortcut.0  43 %
layer4.0.conv1       58 %
layer4.0.bn2         60 %
layer4.0.relu_1      40 %
layer4.0.conv2       78 %
layer4.0.add         76 %
layer4.1.bn1         77 %
layer4.1.relu        58 %
layer4.1.conv1       88 %
layer4.1.bn2         87 %
layer4.1.relu_1      80 %
layer4.1.conv2       87 %
layer4.1.add         87 %

Attack success rate by layer with targeted attack, normal init
conv1                 7 %
layer1.0.bn1          8 %
layer1.0.relu         6 %
layer1.0.conv1       14 %
layer1.0.bn2         11 %
layer1.0.relu_1      14 %
layer1.0.conv2       14 %
layer1.0.add         14 %
layer1.1.bn1         14 %
layer1.1.relu        12 %
layer1.1.conv1       17 %
layer1.1.bn2         18 %
layer1.1.relu_1      13 %
layer1.1.conv2       18 %
layer1.1.add         13 %
layer2.0.bn1         15 %
layer2.0.relu        15 %
layer2.0.shortcut.0  15 %
layer2.0.conv1       18 %
layer2.0.bn2         17 %
layer2.0.relu_1      15 %
layer2.0.conv2       23 %
layer2.0.add         23 %
layer2.1.bn1         22 %
layer2.1.relu        18 %
layer2.1.conv1       28 %
layer2.1.bn2         28 %
layer2.1.relu_1      21 %
layer2.1.conv2       31 %
layer2.1.add         31 %
layer3.0.bn1         30 %
layer3.0.relu        22 %
layer3.0.shortcut.0  27 %
layer3.0.conv1       33 %
layer3.0.bn2         34 %
layer3.0.relu_1      27 %
layer3.0.conv2       35 %
layer3.0.add         38 %
layer3.1.bn1         39 %
layer3.1.relu        31 %
layer3.1.conv1       42 %
layer3.1.bn2         43 %
layer3.1.relu_1      34 %
layer3.1.conv2       48 %
layer3.1.add         47 %
layer4.0.bn1         49 %
layer4.0.relu        38 %
layer4.0.shortcut.0  42 %
layer4.0.conv1       60 %
layer4.0.bn2         59 %
layer4.0.relu_1      39 %
layer4.0.conv2       80 %
layer4.0.add         78 %
layer4.1.bn1         77 %
layer4.1.relu        58 %
layer4.1.conv1       88 %
layer4.1.bn2         87 %
layer4.1.relu_1      80 %
layer4.1.conv2       87 %
layer4.1.add         88 %

Attack success rate by layer with targeted attack, uniform init
conv1                 7 %
layer1.0.bn1          9 %
layer1.0.relu         6 %
layer1.0.conv1       14 %
layer1.0.bn2         12 %
layer1.0.relu_1      13 %
layer1.0.conv2       14 %
layer1.0.add         14 %
layer1.1.bn1         14 %
layer1.1.relu        12 %
layer1.1.conv1       16 %
layer1.1.bn2         17 %
layer1.1.relu_1      13 %
layer1.1.conv2       18 %
layer1.1.add         13 %
layer2.0.bn1         15 %
layer2.0.relu        16 %
layer2.0.shortcut.0  14 %
layer2.0.conv1       19 %
layer2.0.bn2         18 %
layer2.0.relu_1      14 %
layer2.0.conv2       22 %
layer2.0.add         24 %
layer2.1.bn1         21 %
layer2.1.relu        19 %
layer2.1.conv1       27 %
layer2.1.bn2         27 %
layer2.1.relu_1      22 %
layer2.1.conv2       29 %
layer2.1.add         30 %
layer3.0.bn1         30 %
layer3.0.relu        22 %
layer3.0.shortcut.0  25 %
layer3.0.conv1       33 %
layer3.0.bn2         35 %
layer3.0.relu_1      25 %
layer3.0.conv2       34 %
layer3.0.add         36 %
layer3.1.bn1         37 %
layer3.1.relu        32 %
layer3.1.conv1       42 %
layer3.1.bn2         43 %
layer3.1.relu_1      35 %
layer3.1.conv2       47 %
layer3.1.add         47 %
layer4.0.bn1         48 %
layer4.0.relu        37 %
layer4.0.shortcut.0  43 %
layer4.0.conv1       59 %
layer4.0.bn2         60 %
layer4.0.relu_1      37 %
layer4.0.conv2       78 %
layer4.0.add         78 %
layer4.1.bn1         78 %
layer4.1.relu        56 %
layer4.1.conv1       87 %
layer4.1.bn2         88 %
layer4.1.relu_1      79 %
layer4.1.conv2       87 %
layer4.1.add         88 %