-
### ❔ Any questions
I use your bim and pgd code to test my cnn model in MNIST, but get the same accuracy. Is it true?
-
Thanks authors for the great work.
While reviewing the code, I am confused why [overwriting the pgd attack](https://github.com/nblt/Sub-AT/blob/ab7e5192fcb75cd577ed484473abcb2e1870fa83/utils.py#L104…
-
**Describe the bug**
In `future.tf2.attacks.projected_gradient_descent`, the sanity check `clip_min
-
The PGD (and BIM) implementation in this repository is significantly less effective than as reported in prior work. In Table XIV PGD (or BIM) appears to succeed 82.4% (or 75.6%) of the time. When I ru…
-
Hello. I'm interested in your work and have a question about your implementation.
When implementing PGD, I noticed that your code uses only the gradient sign, not the gradient value, as shown in the…
-
Hi.
I have a question on your code in `tensorflow_example.py`.
I think you should add the placeholder `y` to the dictionary `pgd_params`, unless the attack would be performed to reduce the confidenc…
-
While the idea of adversarial training is straightforward—-generate adversarial examples during training and train on those examples until the model learns to classify them correctly—-in practice it i…
-
If I have a matrix of POVM estimators and an identically-shaped matrix of systematic errors corresponding to each element (due to visibility, single-qubit gate infidelities for the state prep and read…
-
Hi @ByungKwanLee and thanks for your work on this repo. I was trying to reproduce some experiments, and if I understood correctly, the MAD pipeline works as follows:
1-Clean pre-training of the mode…
-
Implement a direct projection onto unit simplex insted of an alternating projection.
See https://math.stackexchange.com/questions/2005154/how-to-project-onto-the-unit-simplex-as-intersection-of-two…