-
The PGD (and BIM) implementation in this repository is significantly less effective than as reported in prior work. In Table XIV PGD (or BIM) appears to succeed 82.4% (or 75.6%) of the time. When I ru…
-
Table XIII states that on CIFAR-10 the R+FGSM attack was executed with eps=0.05 and alpha=0.05 whereas the README in the Attack module of the open source code gives eps=0.1 and alpha=0.5. I assume the…
-
Hi,
I was trying this defense with a model with two conv layers trained on MNIST. However,it seems useless, which improves the acc under fgsm from 4.2% to 16.04%. Because of the restriction of my c…
-
I tried to attack BiT and ViT (both from timm pretrained imagenet-21k) by FGSM and I got different results from paper. I have no idea what differences are between this model and that situation.
I …
-
作者你好,关于Train_comdefend_Torch.py文件,我训练enc,dec没有效果,能否提供预训练好的enc、dec的模型,万分感谢!
-
Excuse me.
1. Dataset [GTA5 -> Cityscapes (DeepLab)](https://drive.google.com/open?id=1OBvYVz2ND4ipdfnkhSaseT8yu2ru5n5l) doesn't contain 'synthia_mapped_to_cityscapes' and 'cityscapes_ssl' folder.
2…
-
# My solution for ijcnn19attacks
### If I solved your problem, please reply to this issue to let me know.
### clone from github
```
https://github.com/hfawaz/ijcnn19attacks.git
```
### Cre…
-
### Describe the issue
I am trying to implement FGS on mobile and I want to get the gradient to perturb the original image. Is there a way to extract the gradient from the backward pass by customizin…
-
Hi assistant professor @matthewwicker , I was trying to re-implemented the paper "Individual Fairness in Bayesian Neural Networks" but I get the following error
```
File /opt/conda/lib/python3.10/…
-
It is a basic observation that when given strictly more power, the adversary should never do worse. However, in Table VII the paper reports that MNIST adversarial examples with their l_infinity norm c…