MadryLab / smoothed-vit

Certified Patch Robustness via Smoothed Vision Transformers
https://arxiv.org/abs/2110.07719
MIT License
41 stars 4 forks source link

What's the name of attack did you use? In your paper #2

Closed Nonbiuld closed 1 year ago

Nonbiuld commented 2 years ago

What kind of attack did you use? In your paper, I can‘t find the method which you use to attack all networks.

Hadisalman commented 1 year ago

@Nonbiuld Apologies for late reply, I missed your post. We do not attack our models to evaluate their robustness in this model. We just calculate their certified robust accuracy. The fact that these models are certifiably robust means that we can evaluate their robustness without needing to attack them. Hope this helps!