I have try to execute bash run_pipeline_universal_patch.sh as your steps,but the AP for train with_fp is 0.8548 and the AP for train removed_fp is 0.8618.Why is the AP so close?Can you give me some suggestion?
How many epochs do you need to train to run the defense program? I trained 500,000 epochs, and the ap value on the clean sample was less than 1%, and the ap value on the adversarial sample was less than 40%.
I have try to execute bash run_pipeline_universal_patch.sh as your steps,but the AP for train with_fp is 0.8548 and the AP for train removed_fp is 0.8618.Why is the AP so close?Can you give me some suggestion?
than you~