Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ensemble attack #85

Open
Jialiang14 opened this issue Apr 7, 2022 · 3 comments
Open

ensemble attack #85

Jialiang14 opened this issue Apr 7, 2022 · 3 comments

Comments

@Jialiang14
Copy link

Hello, your job is great! I am confused about one point. If one image could not be perturbed successfully by attacker A, it would be perturbed by attacker B. Then I have a question, attacker B would perturb the original image or the perturbed image by attacker A?

@fra31
Copy link
Owner

fra31 commented Apr 7, 2022

Hi,

thanks! Each attack uses the original (unperturbed) image as target point.

@Jialiang14
Copy link
Author

image

Hello, I use the autoattack with standard and non-individual version. It outputs four robust accuracies under four attacks. Which robust accuracy should I choose at last as the evaluation of the model?

@fra31
Copy link
Owner

fra31 commented May 5, 2022

Hi,

if you're using run_standard_evaluation you should take the last one, which includes all attacks. If instead you use run_standard_evaluation_individual you need to compute the worst-case over the different methods manually.

Hope this helps!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants