A version of AutoAttack wrt L1, which includes the extensions of APGD and Square Attack (Croce & Hein, 2021), is available!.Up-to-date leaderboards are available in RobustBench. The evaluations of models on CIFAR-10 and CIFAR-100 are no longer maintained.We add automatic checks for potential cases where the standard version of AA might be non suitable or sufficient for robustness evaluation. ![]() Note: we fix all the hyperparameters of the attacks, so no tuning is required to test every new classifier. Square Attack, a query-efficient black-box attack (Andriushchenko et al, 2019).FAB, which minimizes the norm of the adversarial perturbations (Croce & Hein, 2019),.APGD-DLR, our new step size-free version of PGD on the new DLR loss,.APGD-CE, our new step size-free version of PGD on the cross-entropy,.We propose to use an ensemble of four diverse attacks to reliably evaluate robustness: "Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks"
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |