carlini/nn_robust_attacks
Robust evasion attacks against neural network to find adversarial examples
PythonBSD-2-Clause
Issues
- 0
- 2
GZip error
#51 opened by ananyag16 - 0
question for self.newimg in l2_attack
#50 opened by lzclzclzc12 - 2
question for l2 distance in l2_attack
#25 opened by ZekunStevenZhang - 1
What version of tensorflow + keras?
#46 opened by kevjunlee - 2
- 0
- 2
Low validation accuracy of CIFAR
#37 opened by HaiQW - 1
Unsuccessful TensorSliceReader constructor
#45 opened by le000043 - 2
Unable to run train_models.py
#44 opened by le000043 - 1
Unable to open file
#43 opened by keerthi4399 - 2
L2 untargeted attack not working?!
#42 opened by as791 - 2
- 1
- 0
modifier always equals zero
#33 opened by overflocat - 7
Setting confidence=0 produces different adversarial accuracy between different runs
#22 opened by ForeverZyh - 0
L_inf always fails if abort_early is False
#39 opened by samuelemarro - 0
- 0
Misleading printing?
#35 opened by FairyOnIce - 0
no boxmin and boxmax in L_0 and L_inf
#34 opened by CNOCycle - 3
About the settings for imagenet
#32 opened by lith0613 - 2
How to control the pixel number to be noised ?
#31 opened by lith0613 - 4
About the hyper parameters for cifar and mnist
#30 opened by lith0613 - 0
- 12
when i run trains_model.py i am getting this error....i am beginner,if any help would be greatfull.
#24 opened by veenah - 5
Unable to generate l2 attack examples
#21 opened by ericcheng09 - 1
Can I run this on a Mac OS?
#28 opened by d4mster - 3
why I only change the weight of the attacked model, the examples are not adversarial any more.
#26 opened by xieyi318 - 5
The performance of l2_attack on Pytorch
#23 opened by zjysteven - 3
Possibility of "fixing" the number of pixels to be modified - L0 attack for MNIST
#19 opened by VishaalMK - 4
l0 not implemented correctly
#16 opened by gehuangyi20 - 1
l0 attack: Potential Bug
#20 opened by ankur6ue - 0
l0 attack can't work correctly
#18 opened by meet-cjli - 3
L_infinite implementation problem
#17 opened by hanwei0912 - 2
li attack clarification
#15 opened by gehuangyi20 - 2
Unable to reproduce L0 attack on MNIST
#14 opened by VishaalMK - 3
Parameter setting for L_0 and L_inf attack
#9 opened by ariewahyu - 2
- 0
Graphdef cannot be larger than 2Gb in tensorflow when using the InceptionModel
#6 opened by shenqixiaojiang - 3
why the adversarial perturbations was damaged by saving the adversarial samples with scipy.misc.
#3 opened by shenqixiaojiang - 1
Contribute implementation to Foolbox
#4 opened by wielandbrendel - 2