diff --git a/docs/dataset_licensing.md b/docs/dataset_licensing.md deleted file mode 100644 index 904f3f183..000000000 --- a/docs/dataset_licensing.md +++ /dev/null @@ -1,158 +0,0 @@ -## Dataset Licensing - -Armory datasets are either licensed or available in accordance to the fair use -exception to copyright infringement. The passthrough license is the same as the original -license for nonadapted datasets. Adapted datasets ("derivative works") are licensed under -the Creative Commons 4.0 International ShareAlike license and are Copyright Two Six Labs, 2020. - -## Original Licenses - -| Dataset | Original license | -|:-:|:-:| -| MNIST | [Creative Commons Attribution-Share Alike 3.0](http://www.pymvpa.org/datadb/mnist.html) | -| CIFAR-10 | [MIT](https://peltarion.com/knowledge-center/documentation/terms/dataset-licenses/cifar-10)| -| Digit | [Creative Commons Attribution-ShareAlike 4.0 International](https://github.com/Jakobovski/free-spoken-digit-dataset) | -| Librispeech | [Creative Commons 4.0](http://www.openslr.org/12/) | -| GTSRB | [CC0 Public Domain](https://www.kaggle.com/meowmeowmeowmeowmeow/gtsrb-german-traffic-sign)| -| Imagenette | [Apache 2.0](https://github.com/fastai/imagenette/blob/master/LICENSE) | -| UCF101 | Fair use exception | -| RESISC45 | Fair use exception | (http://xviewdataset.org/) -| xView | [Creative Commons Attribution-Noncommercial-ShareAlike 4.0 International](https://arxiv.org/pdf/1802.07856) | -| so2sat | [Creative Commons 4.0](https://mediatum.ub.tum.de/1454690) | -| APRICOT | [Apache License Version 2.0](https://apricot.mitre.org/) | -| DAPRICOT | Creative Commons 4.0 | -| CARLA | MIT | -| Speech Commands | [Creative Commons BY 4.0](https://ai.googleblog.com/2017/08/launching-speech-commands-dataset.html) - -## Attributions - -Note: attribution material can be removed upon request to the extent reasonably -practicable. Please direct inquiries to . - -### MNIST -|Attribution | | -|------------------------------|--------------| -| Creator/author name | Yann LeCun and Corinna Cortes | -| Copyright notice | Copyright © 1998 by Yann LeCun and Corinna Cortes | -| Public license notice | http://www.pymvpa.org/datadb/mnist.html | -| Disclaimer notice | UNLESS OTHERWISE MUTUALLY AGREED TO BY THE PARTIES IN WRITING, LICENSOR OFFERS THE WORK AS-IS AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE WORK, EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTIBILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT, OR THE ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OF ABSENCE OF ERRORS, WHETHER OR NOT DISCOVERABLE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO SUCH EXCLUSION MAY NOT APPLY TO YOU. | -| Dataset link | http://yann.lecun.com/exdb/mnist/ | -| Modification | (Slight) Representation of images as binary tensors | -| Citation | LeCun, Yann, Corinna Cortes, and Christopher JC Burges. "The MNIST database of handwritten digits, 1998." URL http://yann.lecun.com/exdb/mnist 10, no. 34 (1998): 14. | - -### CIFAR-10 -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Alex Krizhevsky, Vinod Nair, and Geoffrey Hinton | -| Copyright notice | Copyright © 2013 by Valay Shah | -| Public license notice | https://peltarion.com/knowledge-center/documentation/terms/dataset-licenses/cifar-10 | -| License text (including disclaimer)| Copyright (c) 2013 Valay Shah. Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The foregoing copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.| -| Dataset link | https://www.cs.toronto.edu/~kriz/cifar.html | -| Citation | Krizhevsky, Alex. "Learning Multiple Layers of Features from Tiny Images." URL https://www.cs.toronto.edu/~kriz/learning-features-2009-TR.pdf, (2009). | -| Modification | (Slight) Representation of images as binary tensors | - -### Free Spoken Digit Dataset (FSDD) -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Zohar Jackson, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite| -| Copyright notice | Copyright © 2018 by Zohar Jackson, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite | -| Public license notice | https://github.com/Jakobovski/free-spoken-digit-dataset | -| Disclaimer notice | a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | https://github.com/Jakobovski/free-spoken-digit-dataset | -| Citation | Jackson, Zohar, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite. "Jakobovski/free-spoken-digit-dataset: v1.0.8 (Version v1.0.8)." Zenodo (2018). URL http://doi.org/10.5281/zenodo.134240 | -| Modification | (Slight) Representation of audio wav file as one-dimensional binary tensors | - -### Librispeech -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Vassil Panayotov, Guoguo Chen, Daniel Povey and Sanjeev Khudanpur | -| Copyright notice | Copyright © 2014 by Vassil Panayotov | -| Public license notice | http://www.openslr.org/12/ | -| Disclaimer notice | a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | http://www.openslr.org/12/ | -| Citation | Panayotov, Vassil, Guoguo Chen, Daniel Povey, and Sanjeev Khudanpur. "Librispeech: an ASR corpus based on public domain audio books." In 2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 5206-5210. IEEE, 2015. | -| Modification | (Derivative work) Creation of adversarial dataset that modifies the original audio with small perturbations that are crafted to fool machine learning models. | - -### GTSRB -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel | -| Copyright notice | N/A (public domain) | -| Public license notice | https://www.kaggle.com/meowmeowmeowmeowmeow/gtsrb-german-traffic-sign | -| Disclaimer notice | Affirmer offers the Work as-is and makes no representations or warranties of any kind concerning the Work, express, implied, statutory or otherwise, including without limitation warranties of title, merchantability, fitness for a particular purpose, non infringement, or the absence of latent or other defects, accuracy, or the present or absence of errors, whether or not discoverable, all to the greatest extent permissible under applicable law. Affirmer disclaims responsibility for clearing rights of other persons that may apply to the Work or any use thereof, including without limitation any person's Copyright and Related Rights in the Work. Further, Affirmer disclaims responsibility for obtaining any necessary consents, permissions or other rights required for any use of the Work. | -| Dataset link | http://benchmark.ini.rub.de/?section=gtsrb&subsection=dataset | -| Citation | Stallkamp, Johannes, Marc Schlipsing, Jan Salmen, and Christian Igel. "Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition." Neural Networks, URL http://www.sciencedirect.com/science/article/pii/S0893608012000457, (2012)| -| Modification | (Derivative work) Creation of adversarial dataset that modifies the original images with small perturbations that are crafted to fool machine learning models. | - -### Imagenette -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Jeremy Howard | -| Copyright notice | Copyright © 2019 by Jeremy Howard | -| Public license notice | https://github.com/fastai/imagenette | -| Disclaimer notice | Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License. | -| Dataset link | https://github.com/fastai/imagenette | -| Modification | (Slight) Representation of images as binary tensors | - -### xView -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Defense Innovation Unit Experimental (DIUx) and the National Geospatial-Intelligence Agency (NGA) | -| Copyright notice | None found | -| Public license notice | http://xviewdataset.org/terms.html | -| Disclaimer notice | Disclaimer of Warranties and Limitation of Liability. a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | http://xviewdataset.org/#dataset | -| Modification | (Slight) Representation of images as binary tensors | - -### so2sat -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Xiaoxiang Zhu, Jingliang Hu, Chunping Qiu, Yilei Shi, Jian Kang, Lichao Mou, Hossein Bagheri, Matthias Haeberle, Yuansheng Hua, Rong Huang, Lloyd Hughes, Hao Li, Yao Sun, Guichen Zhang, Shiyao Han, Michael Schmitt, and Yuanyuan Wang | -| Copyright notice | None found | -| Public license notice | https://mediatum.ub.tum.de/1454690 | -| Disclaimer notice | a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU. b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION, NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES, COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR IN PART, THIS LIMITATION MAY NOT APPLY TO YOU. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | https://mediatum.ub.tum.de/1454690 | -| Modification | (Slight) Representation of images as binary tensors | - -### APRICOT -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | A. Braunegg, Amartya Chakraborty, Michael Krumdick, Nicole Lape, Sara Leary, Keith Manville, Elizabeth Merkhofer, Laura Strickhart, and Matthew Walmer | -| Copyright notice | Copyright 2020 APRICOT - MITRE Corporation | -| Public license notice | https://apricot.mitre.org/ | -| Disclaimer notice | Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License. | -| Dataset link | https://apricot.mitre.org/ | -| Modification | (Slight) Representation of images as binary tensors | - -## Fair use notes for RESISC-45 and UCF101 -* Two Six Labs does not charge users for access to the Armory repository, -nor the datasets therein, nor does it derive a profit directly from use of the -datasets. -* Two Six Labs is not merely republishing the original datasets. The -datasets have undergone transformative changes, specifically they have been -repackaged to be integrated with Tensorflow Datasets. This repackaging -includes, but is not limited to, processing images from compressed formats into -binary tensors as well as decoding audio and video files. Further, Two Six Labs -has published derived adversarial datasets that modify the original images/videos with -small perturbations that are crafted to fool machine learning models for both -the RESISC-45 and UCF101 datasets. -* Two Six Labs uses these datasets within Armory, however there are -other additional datasets present, as well as multiple other features present -in Armory beyond providing datasets. -* Two Six Labs attempted to contact the authors of RESISC-45, but received no -response. -* UCF101 direct download functionality has been used by other machine learning -frameworks, such as TensorFlow: https://www.tensorflow.org/datasets/catalog/ucf101 -* Two Six Labs provides public benefit through the public distribution -of the Armory framework to evaluate machine learning models. This material is -based upon work supported by the Defense Advanced Research Projects Agency -(DARPA) under Contract No. HR001120C0114. Any opinions, findings and -conclusions or recommendations expressed in this material are those of the -author(s) and do not necessarily reflect the views of the Defense Advanced -Research Projects Agency (DARPA). - -### Citations for RESISC45 and UCF101 - -Cheng, Gong, Junwei Han, and Xiaoqiang Lu. "Remote sensing image scene classification: Benchmark and state of the art." Proceedings of the IEEE 105, no. 10 (2017): 1865-1883. - -Soomro, Khurram, Amir Roshan Zamir, and Mubarak Shah. "UCF101: A dataset of 101 human actions classes from videos in the wild." arXiv preprint arXiv:1212.0402 (2012). diff --git a/docs/original/CONTRIBUTING.md b/docs/original/CONTRIBUTING.md deleted file mode 100644 index e88c3e752..000000000 --- a/docs/original/CONTRIBUTING.md +++ /dev/null @@ -1,91 +0,0 @@ -Contributing to Armory -====================== -Contributions to Armory are welcomed and highly encouraged! Armory contains a complex suite of tools that both configure the execution -environment and compose a set of objects (from an `experiment` file) to be executed in said environment. - -Primarily, Armory has two main modes of operation: - - Native (also known as `--no-docker`) mode - This uses a pre-set python environment to execute the configuration file. - - Docker - This uses docker to compose and launch docker images, and executes the armory experiments - within the container. - -For more details, including how to set up your development environment for either mode of operation see: [Setting up Development Environment](#Setting-up-the-Development-Environment) - -Armory Development follows the [GitHub Standard Fork & Pull Request Workflow](https://gist.github.com/Chaser324/ce0505fbed06b947d962). - -Armory uses GitHub Actions to test contributions, for more details see [Armory CI](/.github/ci_test.yml). Generally it will be most -useful to set up the [Armory pre-commit hooks](/tools/pre-commit.sh). For more information see the [Armory Style Guide](/docs/style.md). - -## Setting up the Development Environment -Armory follows the [GitHub Standard Fork & Pull Request Workflow](https://gist.github.com/Chaser324/ce0505fbed06b947d962) and therefore, to -get started with contributing to armory, you will first need to head over to [https://github.com/twosixlabs/armory](https://github.com/twosixlabs/armory) -and fork the repo. Once forked, clone that fork to your computer and cd into the forked repo location (herein refered to as `YOUR_ARMORY_REPO`). - -From here, you will need to setup your python virtual environment and, depending on your use case, other applications such as Docker. The following -section will describe the details here in a bit more detail. - -### Native Operation Mode -Armory can run natively within a python virtual environment on a `host` machine. To get setup you will need to -create a [virtual environment](https://docs.python.org/3/library/venv.html). Once created and activated, you will need -to install some additional requirements. Typically, it is useful to use the `-e` flag with the `armory` pip so that it -will point to your local directory, therefore utilizing code edits without requiring follow-on installs. To accomplish -this run: -```bash -cd YOUR_ARMORY_REPO -pip install -e .[developer] -``` -Now that you have the environment setup, kickoff the baseline tests to make sure its all good: -```bash -pytest -s tests/test_host -``` -depending on you `$PATH`, pytest might refer to a pytest outside your virtualenv, which can cause issues. As -an alternative you can use (make sure your virtualenv is active): -```bash -python -m pytest -s tests/test_host -``` - -If this is successful you are off to the races! If you would like to run armory in `--no-docker` mode, see: -[Armory No Docker Setup](/docs/no_docker_mode.md). - -### Docker Operation Mode -Armory can utilize [docker](https://www.docker.com/) to launch containers for execution of armory experiments. -For information on how to install docker on your machine see: [Docker Installation](https://docs.docker.com/get-docker/). - -Once docker is installed, armory downloads and launches containers based on the `__version__` string found in `armory.__init__`. - -Note: only release versions of armory will be published to [Dockerhub](https://hub.docker.com/), therefore, -development branch images much be built locally using: -```bash -cd YOUR_ARMORY_REPO -bash docker/build.sh dev -``` - -## Style Guide -Armory enforces code / file styling using [Flake8](https://flake8.pycqa.org/), [black](https://github.com/psf/black), -[yamllint](https://yamllint.readthedocs.io/en/stable/), etc. For more information about -how we configure these tools, see [Armory Style Guide](/docs/style.md). - -## Pull Requests - -We gladly welcome [pull requests]( -https://help.github.com/articles/about-pull-requests/). - -If you've never done a pull request before we recommend you read -[this guide](http://blog.davidecoppola.com/2016/11/howto-contribute-to-open-source-project-on-github/) -to get you started. - -Before making any changes, we recommend opening an issue (if it -doesn't already exist) and discussing your proposed changes. This will -let us give you advice on the proposed changes. If the changes are -minor, then feel free to make them without discussion. - -## Test Cases -When adding new features please add test cases to ensure their correctness. We use -pytest as our test runner. - -For running `pytest`, users should follow `.github/workflows/ci_test.yml`. -This has tests for docker and native modes as well as formatting. - -## Documentation -When adding new functionality or modifying existing functionality, please update documentation. -Docs are all markdown (`.md`) files located in [docs](/docs/) directory or its subdirectories. -If doc files are added or removed, please also update the [markdown yaml](/mkdocs.yml) diff --git a/docs/original/adversarial_datasets.md b/docs/original/adversarial_datasets.md deleted file mode 100644 index 88a4d848c..000000000 --- a/docs/original/adversarial_datasets.md +++ /dev/null @@ -1,143 +0,0 @@ -# Adversarial Datasets - -The `armory.data.adversarial_datasets` module implements functionality to return adversarial datasets of -various data modalities. By default, this is a NumPy `ArmoryDataGenerator` which -implements the methods needed by the ART framework. - -There are two kinds of adversarial datasets in Armory: *preloaded* as well as *green-screen*. Preloaded datasets contain -examples with universal adversarial perturbations. For preloaded adversarial datasets, `get_batch()` returns -a tuple of `((data_clean, data_adversarial), label_clean)` for a specified batch size in numpy format, -where `data_clean` and `label_clean` represent a clean example and its true label, and `data_adversarial` -represents the corresponding adversarially attacked example. The lone exception is the APRICOT dataset, which is preloaded -but returns a tuple of `(data_adversarial, label_adversarial)` as the images don't have benign counterparts. - -The green-screen adversarial datasets in Armory are DAPRICOT and CARLA. Each image in these datasets contains a -green-screen, for which adversarial patches generated during an attack are inserted onto. For these datasets -`get_batch()` returns a tuple of `(data_adversarial, (objects_label, green_screen_label))`. - - - -Currently, datasets are loaded using TensorFlow Datasets from cached tfrecord files. -If the files are not already present locally in your `dataset_dir` directory, Armory will download them -from Two Six's public S3 dataset repository. - - - -### Green-screen Image and Video Datasets -| `name` | `split` | Description | Source Split | x_shape | x_type | y_shape | Size | -|:----------------------------------:|:--------------------------------------------:|:-----------------------------------------:|:------------:|:-----------------------------------:|:------:|:-------:|:-----------------------------------:| -| "dapricot_dev_adversarial" | ["small", medium", "large", "adversarial"] * | Physical Adversarial Attacks on Object Detection| dev | (nb, 3, 1008, 756, 3) | uint8 | 2-tuple | 81 examples (3 images per example) | -| "dapricot_test_adversarial" | ["small", medium", "large", "adversarial"] * | Physical Adversarial Attacks on Object Detection| test | (nb, 3, 1008, 756, 3) | uint8 | 2-tuple | 324 examples (3 images per example) | -| "carla_obj_det_dev" | ["dev"] | [CARLA Simulator Object Detection](https://carla.org) | dev | (nb=1, 960, 1280, 3 or 6) | uint8 | 2-tuple | 31 images | -| "carla_obj_det_test" | ["test"] | [CARLA Simulator Object Detection](https://carla.org) | test | (nb=1, 960, 1280, 3 or 6) | uint8 | 2-tuple | 30 images | -| "carla_over_obj_det_dev" | ["dev"] | [CARLA Simulator Object Detection](https://carla.org) | dev | (nb=1, 960, 1280, 3 or 6) | uint8 | 2-tuple | 20 images | -| "carla_over_obj_det_test" | ["test"] | [CARLA Simulator Object Detection](https://carla.org) | test | (nb=1, 960, 1280, 3 or 6) |uint8 | 2-tuple | 15 images | -| "carla_video_tracking_dev" | ["dev"] | [CARLA Simulator Video Tracking](https://carla.org) | dev | (nb=1, num_frames, 960, 1280, 3) | uint8 | 2-tuple | 20 videos | -| "carla_video_tracking_test" | ["test"] | [CARLA Simulator Video Tracking](https://carla.org) | test | (nb=1, num_frames, 960, 1280, 3) | uint8 | 2-tuple | 20 videos | -| "carla_multi_object_tracking_dev" | ["dev"] | [CARLA Simulator Multi-object Video Tracking](https://carla.org) | dev | (nb=1, num_frames, 960, 1280, 3) | uint8 | 2-tuple | 20 videos | -| "carla_multi_object_tracking_test" | ["test"] | [CARLA Simulator Multi-object Video Tracking](https://carla.org) | test | (nb=1, num_frames, 960, 1280, 3) | uint8 | 2-tuple | 10 videos | - -\* the "small" split, for example, is the subset of images containing small patch green-screens. Using the "adversarial" split returns the entire dataset. - -##### CARLA Multi-Object Tracking -The ground truth annotation for CARLA multi-object tracking is a 2D NDArray where each row represents a detection with format: ` `. By nature of this dataset, there may be multiple objects present at each timestep; therefore, each object is assigned an ID so that all annotations corresponding to a given object can be identified. -- `timestep`: The timestep indicates which frame this annotation belongs to; indexing begins at 1. -- `object id`: An id referring to the unique object in the frame that this annotation describes. -- `bbox top left x`: The top left x coordinate of the bounding box of this object. -- `bbox top left y`: The top left y coordinate of the bounding box of this object. -- `bbox width`: The width of the bounding box of this object in pixels. -- `bbox height`: The height of the bounding box of this object in pixels. -- `confidence score`: 1 for ground truth objects; models may output values between 0 and 1 to describe the confidence of their predictions. -- `class id`: The class label of this object. -- `visibility`: 1 for all annotations in this dataset. An object that is not visible will not have an annotation for that timestep. - - -##### D-APRICOT -The D-APRICOT dataset does NOT contain labels/bounding boxes for COCO objects, which may occasionally appear in the -background (e.g. car). Each image contains one green screen intended for patch insertion. The green screen shapes vary -between diamond, rectangle, and octagon. A dataset example consists of three images, each of a different camera - angle of the same scene and green screen. The intended threat model is a targeted attack where the inserted patch -is meant to induce the model to predict a specific class at the location of the patch. - - -##### CARLA Object Detection -The carla_obj_det_dev and carla_obj_det_test datasets contain rgb and depth modalities. The modality defaults to `"rgb"` and must be one of `["rgb", "depth", "both"]`. -When using the dataset function imported from [armory.data.adversarial_datasets](../armory/data/adversarial_datasets.py), this value is passed via the `modality` kwarg. When running an Armory scenario, the value is specified in the dataset_config as such: -```json - "dataset": { - "batch_size": 1, - "modality": "rgb", -} -``` -When `modality` is set to `"both"`, the input will be of shape `(nb=1, num_frames, 960, 1280, 6)` where `x[..., :3]` are -the rgb channels and `x[..., 3:]` the depth channels. The depth information is encoded on a log scale in grayscale format (all three depth channels are the same). - -The carla_over_obj_det_dev dataset has the same properties as the above mentioned datasets but is collected utilizing overhead perspectives. In addition, the depth channels are encoded with an [RGB encoding](https://carla.readthedocs.io/en/latest/ref_sensors/#depth-camera). This depth format can be converted to linear grayscale or log grayscale (e.g. for human viewing) using the utility functions in [carla_obj_det_utils.py](../armory/art_experimental/attacks/carla_obj_det_utils.py) - -### Usage of Preloaded Adversarial Datasets -To use a preloaded adversarial dataset for evaluation, set `attack_config["type"]` to `"preloaded"` and specify -the desired values for the `name` and `adversarial_key` keywords in the `attack` module of a scenario configuration. -Valid values for each keyword are given in the table below. - -Example attack module for image classification scenario: -```json -"attack": { - "knowledge": "white", - "kwargs": { - "adversarial_key": "adversarial_univpatch", - "batch_size": 1, - "description": "'adversarial_key' can be 'adversarial_univperturbation' or 'adversarial_univpatch'" - }, - "module": "armory.data.adversarial_datasets", - "name": "resisc45_adversarial_224x224", - "type": "preloaded" -} -``` - -### Preloaded Image Datasets -| `name` | `adversarial_key` | Description | Attack | Source Split | x_shape | x_type | y_shape | y_type | Size | -|:------------------------------:|:------------------------------:|:-----------------------------------------:|:----------------------------------:|:------------:|:----------------:|:------:|:-------:|:------:|:--------------:| -| "imagenet_adversarial" | "adversarial" | ILSVRC12 adversarial image dataset for ResNet50 | Targeted, universal perturbation | test | (nb, 224, 224, 3) |uint8 | (N,) | int64 | 1000 images | -| "resisc45_adversarial_224x224" | "adversarial_univpatch" | REmote Sensing Image Scene Classification | Targeted, universal patch | test | (nb, 224, 224, 3) | uint8 | (N,) | int64 | 5 images/class | -| "resisc45_adversarial_224x224" | "adversarial_univperturbation" | REmote Sensing Image Scene Classification | Untargeted, universal perturbation | test | (nb, 224, 224, 3) | uint8 | (N,) | int64 | 5 images/class | -| "apricot_dev_adversarial" | ["adversarial", frcnn", "ssd", "retinanet"] | [Physical Adversarial Attacks on Object Detection](https://arxiv.org/abs/1912.08166)| Targeted, universal patch | dev | (nb, variable_height, variable_width, 3) | uint8 | n/a | dict | 138 images | -| "apricot_test_adversarial" | ["adversarial", frcnn", "ssd", "retinanet"] | [Physical Adversarial Attacks on Object Detection](https://arxiv.org/abs/1912.08166)| Targeted, universal patch | test | (nb, variable_height, variable_width, 3) | uint8 | n/a | dict | 873 images | - -##### APRICOT -Note: the APRICOT dataset contains splits for ["frcnn", "ssd", "retinanet"] rather than adversarial keys. See example below. -The APRICOT dataset contains labels and bounding boxes for both COCO objects and physical adversarial patches. -The label used to signify the patch is the `ADV_PATCH_MAGIC_NUMBER_LABEL_ID` defined in -[armory/data/adversarial_datasets.py](../armory/data/adversarial_datasets.py). Each image contains one adversarial -patch and a varying number of COCO objects (in some cases zero). COCO object class labels are one-indexed (start from 1) -in Armory <= 0.13.1 and zero-indexed in Armory > 0.13.1. - -```json -"attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "split": "frcnn" - }, - "module": "armory.data.adversarial_datasets", - "name": "apricot_dev_adversarial", - "type": "preloaded", -``` - - -### Preloaded Audio Datasets -| `name` | `adversarial_key` | Description | Attack | Source Split | x_shape | x_type | y_shape | y_type | sampling_rate | Size | -|:-------------------------:|:-----------------:|:--------------------------------------------------:|:----------------------------------:|:------------:|:---------:|:------:|:-------:|:------:|:-------------:|:--------------:| -| "librispeech_adversarial" | "adversarial_perturbation | Librispeech dev dataset for speaker identification | Targeted, universal perturbation | test | (N, variable_length) | int64 | (N,) | int64 | 16 kHz | ~5 sec/speaker | -| "librispeech_adversarial" | "adversarial_univperturbation" | Librispeech dev dataset for speaker identification | Untargeted, universal perturbation | test | (N, variable_length) | int64 | (N,) | int64 | 16 kHz | ~5 sec/speaker | - -### Preloaded Video Datasets -| `name` | `adversarial_key` | Description | Attack | Source Split | x_shape | x_type | y_shape | y_type | Size | -|:----------------------------:|:--------------------------:|:--------------------------:|:----------------------------------:|:------------:|:---------------------------------:|:------:|:-------:|:------:|:--------------:| -| "ucf101_adversarial_112x112" | "adversarial_patch" | UCF 101 Action Recognition | Untargeted, universal perturbation | test | (N, variable_frames, 112, 112, 3) | uint8 | (N,) | int64 | 5 videos/class | -| "ucf101_adversarial_112x112" | "adversarial_perturbation" | UCF 101 Action Recognition | Untargeted, universal perturbation | test | (N, variable_frames, 112, 112, 3) | uint8 | (N,) | int64 | 5 videos/class | - -### Preloaded Poison Datasets -| `name` | `split_type` | Description | Attack | Source Split | x_shape | x_type | y_shape | y_type | Size | -|:------------------------------:|:------------------------------:|:-----------------------------------------:|:----------------------------------:|:------------:|:----------------:|:------:|:-------:|:------:|:--------------:| -| "gtsrb_poison" | poison | German Traffic Sign Poison Dataset | Data poisoning | train | (N, 48, 48, 3) | float32 | (N,) | int64 | 2220 images | -| "gtsrb_poison" | poison_test | German Traffic Sign Poison Dataset | Data poisoning | test | (N, 48, 48, 3) | float32 | (N,) | int64 | 750 images | diff --git a/docs/original/assets/charmory.png b/docs/original/assets/charmory.png deleted file mode 100644 index 7e5f8feba..000000000 Binary files a/docs/original/assets/charmory.png and /dev/null differ diff --git a/docs/original/assets/logo.png b/docs/original/assets/logo.png deleted file mode 100644 index 5ffeb901b..000000000 Binary files a/docs/original/assets/logo.png and /dev/null differ diff --git a/docs/original/baseline_models.md b/docs/original/baseline_models.md deleted file mode 100644 index 4fde37b87..000000000 --- a/docs/original/baseline_models.md +++ /dev/null @@ -1,62 +0,0 @@ -# Baseline Models -Armory has several baseline models available for use in evaluations. All of these -models return an ART wrapped classifier for use with ART attacks and defenses. - - -### Pretrained Weights -Pretrained weights can be loaded in to the baseline models or custom models. This is -achieved by specifying the name in the `weights_file` field of a model's config. - -When the model is loaded it will first try to load the file from the armory -`saved_model_dir`. This enables you to place your own custom weights in that directory -for loading. If the weights file is not found it'll then try to download the file from -our S3 bucket. Files that are available in the armory S3 bucket are listed in the table -below. - -If the `weights_file` is not found locally or in the S3 bucket an error will be -returned. - - -### Keras -The model files can be found in [armory/baseline_models/keras](../armory/baseline_models/keras). - -| Model | S3 weight_files | -|:----------: | :-----------: | -| Cifar10 CNN | | -| Densenet121 CNN | `densenet121_resisc45_v1.h5` , `densenet121_imagenet_v1.h5` | -| Inception_ResNet_v2 CNN | `inceptionresnetv2_imagenet_v1.h5` | -| Micronnet CNN | | -| MNIST CNN | `undefended_mnist_5epochs.h5` | -| ResNet50 CNN | `resnet50_imagenet_v1.h5` | -| so2sat CNN | `multimodal_baseline_weights.h5` | - - -### PyTorch -The model files can be found in [armory/baseline_models/pytorch](../armory/baseline_models/pytorch) - -| Model | S3 weight_files | -|:----------: |:---------------------------------------------:| -| Cifar10 CNN | | -| DeepSpeech 2 | | -| Sincnet CNN | `sincnet_librispeech_v1.pth` | -| MARS | `mars_ucf101_v1.pth` , `mars_kinetics_v1.pth` | -| ResNet50 CNN | `resnet50_imagenet_v1.pth` | -| MNIST CNN | `undefended_mnist_5epochs.pth` | -| xView Faster-RCNN | `xview_model_state_dict_epoch_99_loss_0p67` | -| CARLA Faster-RCNN (rgb)| `carla_rgb_weights_eval5.pt` | -| CARLA Faster-RCNN (depth)| `carla_depth_weights_eval5.pt` | -| CARLA Faster-RCNN (multimodal)| `carla_multimodal_naive_weights.pt` | -| CARLA GoTurn| `pytorch_goturn.pth.tar` | - -### TensorFlow 1 -The model file can be found in [armory/baseline_models/tf_graph](../armory/baseline_models/tf_graph). -The weights for this model are downloaded from the link listed below. - -| Model | TF Weights URL | -|:----------: | :-----------: | -| MSCOCO Faster-RCNN | http://download.tensorflow.org/models/object_detection/faster_rcnn_resnet50_coco_2018_01_28.tar.gz | - - -### Preprocessing Functions -Preprocessing functions have been moved inside each model's forward pass. This is to allow each -model to receive as input the canonicalized form of a dataset. \ No newline at end of file diff --git a/docs/original/baseline_results/apricot_results.md b/docs/original/baseline_results/apricot_results.md deleted file mode 100644 index 412e817a9..000000000 --- a/docs/original/baseline_results/apricot_results.md +++ /dev/null @@ -1,12 +0,0 @@ -# APRICOT Object Detection Baseline Evaluation (Updated December 2020) - -* **Baseline Model Performance: (results obtained using Armory v0.13)** - * Baseline MSCOCO Objects mAP: 8.76% (all test examples) - * Baseline Targeted Patch mAP: 5.70% (all test examples) -* **Baseline Defense Performance: (results obtained using Armory v0.13)** -Baseline defense is art_experimental.defences.jpeg_compression_normalized(clip_values=(0.0, 1.0), quality=10, -channel_index=3, apply_fit=False, apply_predict=True).\ -Baseline defense performance is evaluated for a transfer attack. - * Baseline MSCOCO Objects mAP: 7.83% (all test examples) - * Baseline Targeted Patch mAP: 4.59% (all test examples) - diff --git a/docs/original/baseline_results/carla_mot_results.md b/docs/original/baseline_results/carla_mot_results.md deleted file mode 100644 index 2cc5bf849..000000000 --- a/docs/original/baseline_results/carla_mot_results.md +++ /dev/null @@ -1,17 +0,0 @@ -# CARLA MOT Baseline Evaluations - -This is the baseline evaluation for the multi-object tracking scenario. For single-object tracking, see [carla_video_tracking_results.md](../baseline_results/carla_video_tracking_results.md). - -For [dev data](https://github.com/twosixlabs/armory/blob/master/armory/data/adversarial/carla_mot_dev.py), results obtained using Armory v0.16.1. - - -| Data | Defended | Attack | Attack Parameters | Benign DetA / AssA / HOTA | Adversarial DetA / AssA / HOTA | Test Size | -|------|----------|-------------------|--------------------------------|---------------------------|--------------------------------|-----------| -| Dev | no | Adversarial Patch | step_size=0.02, max_iter=100 | 0.49 / 0.62 / 0.55 | 0.14 / 0.57 / 0.29 | 20 | -| Dev | no | Robust DPatch | step_size=0.002, max_iter=1000 | 0.49 / 0.62 / 0.55 | 0.37 / 0.60 / 0.47 | 20 | -| Dev | yes | Robust DPatch | step_size=0.002, max_iter=1000 | 0.34 / 0.52 / 0.42 | 0.24 / 0.50 / 0.34 | 20 | - -Defended results not available for Adversarial Patch attack because JPEG Compression defense is not implemented in PyTorch and so is not fully differentiable. -Note that Robust DPatch is considerably slower than Adversarial Patch. - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/master/scenario_configs/eval6/carla_mot) \ No newline at end of file diff --git a/docs/original/baseline_results/carla_od_results.md b/docs/original/baseline_results/carla_od_results.md deleted file mode 100644 index f43070e70..000000000 --- a/docs/original/baseline_results/carla_od_results.md +++ /dev/null @@ -1,57 +0,0 @@ -# CARLA Object Detection Baseline Evaluations - -## CARLA Street Level OD Dataset -(For [dev data](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/data/adversarial/carla_obj_det_dev.py), results are obtained using Armory v0.15.2; for [test data](https://github.com/twosixlabs/armory/blob/v0.15.4/armory/data/adversarial/carla_obj_det_test.py), results are obtained using Armory v0.15.4)** - -Single Modality (RGB) Object Detection - -| Data | Attack | Attack Parameters | Benign mAP | Benign Disappearance Rate | Benign Hallucination per Image | Benign Misclassification Rate | Benign True Positive Rate | Adversarial mAP | Adversarial Disappearance Rate | Adversarial Hallucination per Image | Adversarial Misclassification Rate | Adversarial True Positive Rate | Test Size | -|------|-------------------|------------------------------------|-------------|-----------------------------|----------------------------------|---------------------------------|-----------------------------|------------------|----------------------------------|--------------------------------------|-------------------------------------|---------------------------------|-----------| -| Dev | Robust DPatch | learning_rate=0.002, max_iter=2000 | 0.76/0.72 | 0.19/0.22 | 3.97/3.48 | 0.06/0.06 | 0.75/0.71 | 0.68/0.66 | 0.27/0.28 | 4.48/3.65 | 0.06/0.07 | 0.67/0.65 | 31 | -| Dev | Adversarial Patch | learning_rate=0.003, max_iter=1000 | 0.76/0.72 | 0.19/0.22 | 3.97/3.48 | 0.06/0.06 | 0.75/0.71 | 0.54/* | 0.32/* | 22.16/* | 0.05/* | 0.62/* | 31 | -| Test | Robust DPatch | learning_rate=0.002, max_iter=2000 | 0.79/0.74 | 0.16/0.25 | 4.10/3.50 | 0.03/0.01 | 0.82/0.75 | 0.72/0.64 | 0.32/0.39 | 4.80/4.0 | 0.03/0.01 | 0.65/0.60 | 20 | -| Test | Adversarial Patch | learning_rate=0.003, max_iter=1000 | 0.79/0.74 | 0.16/0.25 | 4.10/3.50 | 0.03/0.01 | 0.82/0.75 | 0.38/* | 0.40/* | 42.55/* | 0.03/* | 0.57/* | 20 | - -Multimodality (RGB+depth) Object Detection - -| Data | Attack | Attack Parameters | Benign mAP | Benign Disappearance Rate | Benign Hallucination per Image | Benign Misclassification Rate | Benign True Positive Rate | Adversarial mAP | Adversarial Disappearance Rate | Adversarial Hallucination per Image | Adversarial Misclassification Rate | Adversarial True Positive Rate | Test Size | -|------|-------------------|--------------------------------------------------------------------------------------|-------------|-----------------------------|----------------------------------|---------------------------------|-----------------------------|------------------|----------------------------------|--------------------------------------|-------------------------------------|---------------------------------|-----------| -| Dev | Robust DPatch | depth_delta_meters=3, learning_rate=0.002, learning_rate_depth=0.0001, max_iter=2000 | 0.87/0.86 | 0.06/0.04 | 1.23/2.55 | 0.05/0.05 | 0.88/0.91 | 0.76/0.83 | 0.10/0.06 | 5.68/4.87 | 0.05/0.05 | 0.84/0.89 | 31 | -| Dev | Adversarial Patch | depth_delta_meters=3, learning_rate=0.003, learning_rate_depth=0.0001, max_iter=1000 | 0.87/0.86 | 0.06/0.04 | 1.23/2.55 | 0.05/0.05 | 0.88/0.91 | 0.66/0.76 | 0.11/0.10 | 10.74/7.13 | 0.06/0.05 | 0.83/0.85 | 31 | -| Test | Robust DPatch | depth_delta_meters=3, learning_rate=0.002, learning_rate_depth=0.0001, max_iter=2000 | 0.90/0.89 | 0.03/0.04 | 1.0/1.45 | 0.03/0.02 | 0.94/0.94 | 0.81/0.89 | 0.13/0.06 | 4.75/2.05 | 0.03/0.02 | 0.83/0.91 | 20 | -| Test | Adversarial Patch | depth_delta_meters=3, learning_rate=0.003, learning_rate_depth=0.0001, max_iter=1000 | 0.90/0.89 | 0.03/0.04 | 1.0/1.45 | 0.03/0.02 | 0.94/0.94 | 0.50/0.57 | 0.21/0.14 | 22.55/13.70 | 0.04/0.03 | 0.75/0.83 | 20 | - -a/b in the tables refer to undefended/defended performance results, respectively. - -\* Defended results not available for Adversarial Patch attack against single modality because JPEG Compression defense is not implemented in PyTorch and so is not fully differentiable - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/v0.15.4/scenario_configs/eval5/carla_object_detection) - - -## CARLA Overhead OD Dataset - -Dev data results obtained using Armory 0.16.0, Test data results obtained using Armory 0.16.1 - -Single Modality (RGB) Object Detection - -| Data | Defended | Attack | Attack Parameters | Benign mAP | Benign Disappearance Rate | Benign Hallucination per Image | Benign Misclassification Rate | Benign True Positive Rate | Adversarial mAP | Adversarial Disappearance Rate | Adversarial Hallucination per Image | Adversarial Misclassification Rate | Adversarial True Positive Rate | Test Size | -|------|----------|-------------------|------------------------------------|-------------|-----------------------------|----------------------------------|---------------------------------|-----------------------------|------------------|----------------------------------|--------------------------------------|-------------------------------------|---------------------------------|-----------| -| Dev | no | Adversarial Patch | learning_rate=0.003, max_iter=1000 | 0.64 | 0.36 | 1.9 | 0.02 | 0.62 | 0.16 | 0.64 | 31.0 | 0.009 | 0.35 | 20 | -| Dev | no | Robust DPatch | learning_rate=0.002, max_iter=2000 | 0.64 | 0.36 | 1.9 | 0.02 | 0.62 | 0.42 | 0.43 | 12.0 | 0.009 | 0.56 | 20 | -| Dev | yes | Robust DPatch | learning_rate=0.002, max_iter=2000 | 0.51 | 0.44 | 3.1 | 0.02 | 0.54 | 0.41 | 0.52 | 9.8 | 0.01 | 0.47 | 20 | -| Test | no | Adversarial Patch | learning_rate=0.003, max_iter=1000 | 0.60 | 0.42 | 3.6 | 0.03 | 0.55 | 0.04 | 0.81 | 54.1 | 0.0 | 0.19 | 15 | - -Multimodality (RGB+depth) Object Detection - -| Data | Defended | Attack | Attack Parameters | Benign mAP | Benign Disappearance Rate | Benign Hallucination per Image | Benign Misclassification Rate | Benign True Positive Rate | Adversarial mAP | Adversarial Disappearance Rate | Adversarial Hallucination per Image | Adversarial Misclassification Rate | Adversarial True Positive Rate | Test Size | -|------|----------|-------------------|-----------------------------------------------------------------------------------------|-------------|-----------------------------|----------------------------------|---------------------------------|-----------------------------|------------------|----------------------------------|--------------------------------------|-------------------------------------|---------------------------------|-----------| -| Dev | no | Adversarial Patch | depth_delta_meters=0.03, learning_rate=0.003, learning_rate_depth=0.0001, max_iter=1000 | 0.63 | 0.38 | 0.7 | 0.02 | 0.61 | 0.39 | 0.53 | 5.0 | 0.02 | 0.45 | 20 | -| Dev | yes | Adversarial Patch | depth_delta_meters=0.03, learning_rate=0.003, learning_rate_depth=0.0001, max_iter=1000 | 0.67 | 0.34 | 0.9 | 0.02 | 0.64 | 0.56 | 0.48 | 1.1 | 0.02 | 0.50 | 20 | -| Dev | no | Robust DPatch | depth_delta_meters=0.03, learning_rate=0.002, learning_rate_depth=0.0001, max_iter=2000 | 0.63 | 0.38 | 0.7 | 0.02 | 0.61 | 0.54 | 0.42 | 0.65 | 0.02 | 0.56 | 20 | -| Dev | yes | Robust DPatch | depth_delta_meters=0.03, learning_rate=0.002, learning_rate_depth=0.0001, max_iter=2000 | 0.67 | 0.34 | 0.9 | 0.02 | 0.64 | 0.65 | 0.38 | 0.9 | 0.02 | 0.60 | 20 | -| Test | no | Adversarial Patch | depth_delta_meters=0.03, learning_rate=0.003, learning_rate_depth=0.0001, max_iter=1000 | 0.58 | 0.39 | 0.8 | 0.03 | 0.58 | 0.19 | 0.72 | 15.8 | 0.01 | 0.23 | 15 | - - -Defended results not available for Adversarial Patch attack against single modality because JPEG Compression defense is not implemented in PyTorch and so is not fully differentiable - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/master/scenario_configs/eval6/carla_overhead_object_detection) \ No newline at end of file diff --git a/docs/original/baseline_results/carla_video_tracking_results.md b/docs/original/baseline_results/carla_video_tracking_results.md deleted file mode 100644 index 792f46926..000000000 --- a/docs/original/baseline_results/carla_video_tracking_results.md +++ /dev/null @@ -1,15 +0,0 @@ -# CARLA Video Tracking Baseline Evaluation - -This is the baseline evaluation for the single-object tracking scenario. For multi-object tracking, see [carla_mot_results.md](../baseline_results/carla_mot_results.md). - -For [dev data](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/data/adversarial/carla_video_tracking_dev.py), results obtained using Armory v0.15.2. -For [test data](https://github.com/twosixlabs/armory/blob/v0.15.4/armory/data/adversarial/carla_video_tracking_test.py), results obtained using Armory v0.15.4. - -| Data | Attack Parameters | Benign Mean IoU | Benign Mean Success Rate | Adversarial Mean IoU | Adversarial Mean Success Rate | Test Size | -|------|------------------------------|-----------------|--------------------------|----------------------|-------------------------------|-----------| -| Dev | step_size=0.02, max_iter=100 | 0.55/0.57 | 0.57/0.60 | 0.14/0.19 | 0.15/0.20 | 20 | -| Test | step_size=0.02, max_iter=100 | 0.52/0.45 | 0.54/0.47 | 0.15/0.17 | 0.16/0.18 | 20 | - -a/b in the tables refer to undefended/defended performance results, respectively. - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/v0.15.4/scenario_configs/eval5/carla_video_tracking) \ No newline at end of file diff --git a/docs/original/baseline_results/cifar10_dlbd_results.md b/docs/original/baseline_results/cifar10_dlbd_results.md deleted file mode 100644 index a03111677..000000000 --- a/docs/original/baseline_results/cifar10_dlbd_results.md +++ /dev/null @@ -1,468 +0,0 @@ -# Cifar10 Dirty-label Backdoor Baseline Evaluation - -## Copyright Trigger - -### Undefended - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.826 | 0.820 | 0.825 | 0.824 | 0.003 | -| 01 | 0.814 | 0.831 | 0.816 | 0.820 | 0.008 | -| 05 | 0.814 | 0.799 | 0.822 | 0.812 | 0.010 | -| 10 | 0.789 | 0.789 | 0.803 | 0.794 | 0.007 | -| 20 | 0.772 | 0.758 | 0.770 | 0.767 | 0.006 | -| 30 | 0.759 | 0.720 | 0.759 | 0.746 | 0.018 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.764 | 0.771 | 0.765 | 0.767 | 0.003 | -| 01 | 0.764 | 0.763 | 0.758 | 0.762 | 0.002 | -| 05 | 0.762 | 0.768 | 0.766 | 0.765 | 0.002 | -| 10 | 0.762 | 0.764 | 0.767 | 0.764 | 0.002 | -| 20 | 0.760 | 0.758 | 0.757 | 0.758 | 0.001 | -| 30 | 0.761 | 0.688 | 0.763 | 0.737 | 0.035 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.285 | 0.173 | 0.226 | 0.228 | 0.046 | -| 05 | 0.615 | 0.641 | 0.615 | 0.624 | 0.012 | -| 10 | 0.781 | 0.783 | 0.767 | 0.777 | 0.007 | -| 20 | 0.852 | 0.866 | 0.879 | 0.866 | 0.011 | -| 30 | 0.896 | 0.854 | 0.887 | 0.879 | 0.018 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.725 | 0.727 | 0.720 | 0.724 | 0.003 | -| 05 | 0.701 | 0.706 | 0.704 | 0.704 | 0.002 | -| 10 | 0.693 | 0.695 | 0.697 | 0.695 | 0.001 | -| 20 | 0.689 | 0.687 | 0.685 | 0.687 | 0.002 | -| 30 | 0.689 | 0.620 | 0.691 | 0.666 | 0.033 | - - - -### Random Filter - - -**Accuracy on Benign Test Data Source Class** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.788|0.81 |0.814|0.804 |0.01143095213 | -|1% |0.777|0.773|0.795|0.7816666667|0.00956846673 | -|5% |0.726|0.78 |0.764|0.7566666667|0.02264705034 | -|10% |0.773|0.756|0.772|0.767 |0.007788880964| -|20% |0.743|0.762|0.752|0.7523333333|0.007760297818| -|30% |0.73 |0.73 |0.726|0.7286666667|0.001885618083| - - -**Accuracy on Benign Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.734|0.741|0.741|0.7386666667|0.003299831646| -|1% |0.732|0.724|0.738|0.7313333333|0.005734883511| -|5% |0.716|0.722|0.738|0.7253333333|0.009285592185| -|10% |0.735|0.722|0.73 |0.729 |0.005354126135| -|20% |0.725|0.723|0.735|0.7276666667|0.005249338583| -|30% |0.729|0.727|0.73 |0.7286666667|0.001247219129| - - -**Attack Success Rate** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% | - | - | - | - | - | -|1% |0.215|0.235|0.264|0.238 |0.02011632836 | -|5% |0.639|0.579|0.651|0.623 |0.0314960315 | -|10% |0.733|0.686|0.721|0.7133333333|0.01993879524 | -|20% |0.865|0.837|0.839|0.847 |0.01275408431 | -|30% |0.877|0.892|0.875|0.8813333333|0.007586537784| - - -**Accuracy on Poisoned Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% | - | - | - | - | - | -|1% |0.698|0.688|0.694|0.6933333333|0.004109609335| -|5% |0.659|0.665|0.679|0.6676666667|0.00837987006 | -|10% |0.668|0.66 |0.666|0.6646666667|0.003399346342| -|20% |0.656|0.653|0.665|0.658 |0.005099019514| -|30% |0.66 |0.657|0.661|0.6593333333|0.001699673171| - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.824 | 0.816 | 0.811 | 0.817 | 0.005 | -| 01 | 0.833 | 0.820 | 0.834 | 0.829 | 0.006 | -| 05 | 0.716 | 0.712 | 0.729 | 0.719 | 0.007 | -| 10 | 0.812 | 0.801 | 0.811 | 0.808 | 0.005 | -| 20 | 0.789 | 0.810 | 0.788 | 0.796 | 0.010 | -| 30 | 0.802 | 0.755 | 0.768 | 0.775 | 0.020 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.774 | 0.765 | 0.772 | 0.770 | 0.004 | -| 01 | 0.770 | 0.764 | 0.771 | 0.768 | 0.003 | -| 05 | 0.760 | 0.764 | 0.766 | 0.763 | 0.002 | -| 10 | 0.767 | 0.766 | 0.769 | 0.767 | 0.001 | -| 20 | 0.770 | 0.767 | 0.764 | 0.767 | 0.002 | -| 30 | 0.766 | 0.760 | 0.763 | 0.763 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.049 | 0.042 | 0.062 | 0.051 | 0.008 | -| 05 | 0.091 | 0.085 | 0.106 | 0.094 | 0.009 | -| 10 | 0.068 | 0.089 | 0.087 | 0.081 | 0.009 | -| 20 | 0.069 | 0.073 | 0.060 | 0.067 | 0.005 | -| 30 | 0.067 | 0.099 | 0.077 | 0.081 | 0.013 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.745 | 0.741 | 0.747 | 0.744 | 0.002 | -| 05 | 0.728 | 0.741 | 0.737 | 0.735 | 0.005 | -| 10 | 0.737 | 0.740 | 0.743 | 0.740 | 0.002 | -| 20 | 0.746 | 0.739 | 0.736 | 0.740 | 0.005 | -| 30 | 0.737 | 0.732 | 0.735 | 0.735 | 0.002 | - - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.801 | 0.760 | 0.671 | 0.744 | 0.054 | -| 01 | 0.817 | 0.770 | 0.772 | 0.786 | 0.022 | -| 05 | 0.785 | 0.778 | 0.755 | 0.773 | 0.013 | -| 10 | 0.735 | 0.565 | 0.753 | 0.684 | 0.085 | -| 20 | 0.741 | 0.734 | 0.688 | 0.721 | 0.024 | -| 30 | 0.684 | 0.673 | 0.667 | 0.675 | 0.007 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.724 | 0.719 | 0.706 | 0.716 | 0.007 | -| 01 | 0.720 | 0.728 | 0.718 | 0.722 | 0.004 | -| 05 | 0.707 | 0.720 | 0.697 | 0.708 | 0.009 | -| 10 | 0.712 | 0.670 | 0.709 | 0.697 | 0.019 | -| 20 | 0.724 | 0.730 | 0.726 | 0.727 | 0.003 | -| 30 | 0.720 | 0.707 | 0.705 | 0.711 | 0.007 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.255 | 0.228 | 0.263 | 0.249 | 0.015 | -| 05 | 0.523 | 0.439 | 0.463 | 0.475 | 0.035 | -| 10 | 0.665 | 0.739 | 0.679 | 0.694 | 0.032 | -| 20 | 0.692 | 0.838 | 0.822 | 0.784 | 0.065 | -| 30 | 0.916 | 0.888 | 0.887 | 0.897 | 0.013 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.684 | 0.694 | 0.678 | 0.685 | 0.006 | -| 05 | 0.652 | 0.670 | 0.644 | 0.655 | 0.011 | -| 10 | 0.654 | 0.619 | 0.651 | 0.641 | 0.016 | -| 20 | 0.666 | 0.663 | 0.662 | 0.664 | 0.002 | -| 30 | 0.654 | 0.642 | 0.641 | 0.646 | 0.006 | - - - -### Spectral Signatures - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.784 | 0.782 | 0.755 | 0.774 | 0.013 | -| 01 | 0.770 | 0.771 | 0.776 | 0.772 | 0.003 | -| 05 | 0.739 | 0.748 | 0.767 | 0.751 | 0.012 | -| 10 | 0.727 | 0.726 | 0.745 | 0.733 | 0.009 | -| 20 | 0.736 | 0.715 | 0.731 | 0.727 | 0.009 | -| 30 | 0.669 | 0.646 | 0.677 | 0.664 | 0.013 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.655 | 0.696 | 0.696 | 0.682 | 0.019 | -| 01 | 0.667 | 0.628 | 0.637 | 0.644 | 0.017 | -| 05 | 0.699 | 0.694 | 0.647 | 0.680 | 0.023 | -| 10 | 0.692 | 0.688 | 0.695 | 0.692 | 0.003 | -| 20 | 0.694 | 0.687 | 0.643 | 0.674 | 0.023 | -| 30 | 0.677 | 0.686 | 0.693 | 0.686 | 0.007 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.219 | 0.222 | 0.235 | 0.225 | 0.007 | -| 05 | 0.531 | 0.498 | 0.323 | 0.451 | 0.091 | -| 10 | 0.535 | 0.722 | 0.560 | 0.606 | 0.083 | -| 20 | 0.682 | 0.715 | 0.665 | 0.687 | 0.021 | -| 30 | 0.791 | 0.831 | 0.863 | 0.828 | 0.029 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.635 | 0.597 | 0.599 | 0.610 | 0.018 | -| 05 | 0.646 | 0.642 | 0.611 | 0.633 | 0.016 | -| 10 | 0.640 | 0.626 | 0.641 | 0.636 | 0.007 | -| 20 | 0.636 | 0.627 | 0.585 | 0.616 | 0.023 | -| 30 | 0.617 | 0.628 | 0.629 | 0.625 | 0.006 | - - - - - - - - - -## Watermark Trigger - -### Undefended - -**Accuracy on Benign Test Data Source Class** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.822|0.84 |0.831|0.831 |0.007348469228| -|1% |0.817|0.832|0.822|0.8236666667|0.006236095645| -|5% |0.82 |0.752|0.82 |0.7973333333|0.03205550741 | -|10% |0.796|0.801|0.799|0.7986666667|0.002054804668| -|20% |0.794|0.789|0.783|0.7886666667|0.004496912521| -|30% |0.77 |0.774|0.784|0.776 |0.005887840578| - -**Accuracy on Benign Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.772|0.772|0.764|0.7693333333|0.003771236166| -|1% |0.761|0.766|0.764|0.7636666667|0.002054804668| -|5% |0.765|0.74 |0.768|0.7576666667|0.01255211359 | -|10% |0.763|0.761|0.762|0.762 |0.0008164965809| -|20% |0.769|0.766|0.762|0.7656666667|0.002867441756| -|30% |0.764|0.762|0.769|0.765 |0.002943920289| - - -**Attack Success Rate** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |- |- |- |- |- | -|1% |0.298|0.454|0.268|0.34 |0.08153526844 | -|5% |0.802|0.757|0.734|0.7643333333|0.02824102611 | -|10% |0.87 |0.89 |0.846|0.8686666667|0.01798765008 | -|20% |0.93 |0.941|0.946|0.939 |0.006683312552| -|30% |0.93 |0.952|0.96 |0.9473333333|0.01268419839 | - - -**Accuracy on Poisoned Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |- |- |- |- |- | -|1% |0.731|0.72 |0.735|0.7286666667|0.006342099197| -|5% |0.692|0.678|0.703|0.691 |0.01023067284 | -|10% |0.691|0.686|0.691|0.6893333333|0.002357022604| -|20% |0.693|0.691|0.686|0.69 |0.002943920289| -|30% |0.69 |0.687|0.693|0.69 |0.002449489743| - - - -### Random Filter - -**Accuracy on Benign Test Data Source Class** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.792|0.799|0.799|0.7966666667|0.003299831646| -|1% |0.785|0.781|0.772|0.7793333333|0.005436502143| -|5% |0.795|0.774|0.78 |0.783 |0.008831760866| -|10% |0.755|0.765|0.765|0.7616666667|0.004714045208| -|20% |0.754|0.741|0.739|0.7446666667|0.006649979114| -|30% |0.78 |0.707|0.715|0.734 |0.03269046752 | - - -**Accuracy on Benign Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0.731|0.738|0.733|0.734 |0.002943920289| -|1% |0.733|0.72 |0.731|0.728 |0.005715476066| -|5% |0.742|0.725|0.733|0.7333333333|0.006944222219| -|10% |0.728|0.728|0.735|0.7303333333|0.003299831646| -|20% |0.735|0.729|0.737|0.7336666667|0.003399346342| -|30% |0.727|0.716|0.731|0.7246666667|0.006342099197| - - -**Attack Success Rate** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0 |0 |0 |0 |0 | -|1% |0.268|0.247|0.259|0.258 |0.008602325267| -|5% |0.747|0.696|0.667|0.7033333333|0.03306895153 | -|10% |0.794|0.834|0.809|0.8123333333|0.01649915823 | -|20% |0.918|0.897|0.906|0.907 |0.008602325267| -|30% |0.935|0.95 |0.947|0.944 |0.006480740698| - - -**Accuracy on Poisoned Test Data All Classes** - -|Poison Ratio|Run 1|Run 2|Run 3|Mean |Std | -|------------|-----|-----|-----|------------|--------------| -|0% |0 |0 |0 |0 |0 | -|1% |0.708|0.692|0.702|0.7006666667|0.006599663291| -|5% |0.677|0.663|0.676|0.672 |0.006377042157| -|10% |0.665|0.659|0.669|0.6643333333|0.004109609335| -|20% |0.663|0.659|0.667|0.663 |0.003265986324| -|30% |0.652|0.647|0.662|0.6536666667|0.006236095645| - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.817 | 0.822 | 0.827 | 0.822 | 0.004 | -| 01 | 0.825 | 0.830 | 0.809 | 0.821 | 0.009 | -| 05 | 0.818 | 0.817 | 0.802 | 0.812 | 0.007 | -| 10 | 0.795 | 0.800 | 0.801 | 0.799 | 0.003 | -| 20 | 0.787 | 0.792 | 0.788 | 0.789 | 0.002 | -| 30 | 0.761 | 0.761 | 0.775 | 0.766 | 0.007 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.771 | 0.765 | 0.775 | 0.771 | 0.004 | -| 01 | 0.768 | 0.764 | 0.764 | 0.765 | 0.002 | -| 05 | 0.767 | 0.767 | 0.766 | 0.767 | 0.000 | -| 10 | 0.769 | 0.759 | 0.766 | 0.765 | 0.004 | -| 20 | 0.765 | 0.763 | 0.761 | 0.763 | 0.002 | -| 30 | 0.763 | 0.758 | 0.762 | 0.761 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.020 | 0.039 | 0.039 | 0.033 | 0.009 | -| 05 | 0.029 | 0.024 | 0.022 | 0.025 | 0.003 | -| 10 | 0.016 | 0.025 | 0.036 | 0.026 | 0.008 | -| 20 | 0.038 | 0.023 | 0.030 | 0.030 | 0.006 | -| 30 | 0.023 | 0.027 | 0.030 | 0.027 | 0.003 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.764 | 0.757 | 0.761 | 0.761 | 0.003 | -| 05 | 0.763 | 0.760 | 0.764 | 0.763 | 0.002 | -| 10 | 0.769 | 0.756 | 0.762 | 0.762 | 0.005 | -| 20 | 0.759 | 0.755 | 0.758 | 0.757 | 0.002 | -| 30 | 0.760 | 0.755 | 0.760 | 0.758 | 0.002 | - - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.806 | 0.815 | 0.786 | 0.802 | 0.012 | -| 01 | 0.773 | 0.789 | 0.768 | 0.777 | 0.009 | -| 05 | 0.504 | 0.658 | 0.608 | 0.590 | 0.064 | -| 10 | 0.734 | 0.726 | 0.700 | 0.720 | 0.015 | -| 20 | 0.680 | 0.664 | 0.656 | 0.667 | 0.010 | -| 30 | 0.932 | 0.652 | 0.697 | 0.760 | 0.123 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.732 | 0.756 | 0.703 | 0.731 | 0.022 | -| 01 | 0.722 | 0.722 | 0.720 | 0.721 | 0.001 | -| 05 | 0.691 | 0.721 | 0.712 | 0.708 | 0.012 | -| 10 | 0.724 | 0.720 | 0.709 | 0.718 | 0.007 | -| 20 | 0.708 | 0.707 | 0.698 | 0.704 | 0.005 | -| 30 | 0.097 | 0.722 | 0.730 | 0.516 | 0.296 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.282 | 0.186 | 0.167 | 0.212 | 0.050 | -| 05 | 0.966 | 0.985 | 0.984 | 0.978 | 0.009 | -| 10 | 0.673 | 0.852 | 0.284 | 0.603 | 0.237 | -| 20 | 0.741 | 0.678 | 0.947 | 0.789 | 0.115 | -| 30 | 0.000 | 0.962 | 0.947 | 0.636 | 0.450 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.696 | 0.701 | 0.701 | 0.699 | 0.002 | -| 05 | 0.641 | 0.655 | 0.652 | 0.649 | 0.006 | -| 10 | 0.670 | 0.655 | 0.688 | 0.671 | 0.014 | -| 20 | 0.653 | 0.659 | 0.634 | 0.649 | 0.011 | -| 30 | 0.100 | 0.657 | 0.663 | 0.473 | 0.264 | - - - -### Spectral Signatures - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.757 | 0.786 | 0.763 | 0.769 | 0.012 | -| 01 | 0.779 | 0.770 | 0.776 | 0.775 | 0.004 | -| 05 | 0.757 | 0.115 | 0.753 | 0.542 | 0.302 | -| 10 | 0.751 | 0.700 | 0.754 | 0.735 | 0.025 | -| 20 | 0.746 | 0.706 | 0.735 | 0.729 | 0.017 | -| 30 | 0.613 | 0.655 | 0.649 | 0.639 | 0.019 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | 0.702 | 0.703 | 0.705 | 0.703 | 0.001 | -| 01 | 0.692 | 0.689 | 0.689 | 0.690 | 0.001 | -| 05 | 0.701 | 0.090 | 0.687 | 0.492 | 0.285 | -| 10 | 0.694 | 0.688 | 0.634 | 0.672 | 0.027 | -| 20 | 0.681 | 0.692 | 0.688 | 0.687 | 0.004 | -| 30 | 0.689 | 0.695 | 0.685 | 0.689 | 0.004 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.105 | 0.141 | 0.117 | 0.121 | 0.015 | -| 05 | 0.129 | 0.000 | 0.180 | 0.103 | 0.076 | -| 10 | 0.356 | 0.786 | 0.601 | 0.581 | 0.176 | -| 20 | 0.905 | 0.697 | 0.890 | 0.831 | 0.095 | -| 30 | 0.814 | 0.848 | 0.140 | 0.601 | 0.326 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 00 | - |- |- |- |- | -| 01 | 0.678 | 0.674 | 0.677 | 0.676 | 0.002 | -| 05 | 0.690 | 0.085 | 0.675 | 0.483 | 0.282 | -| 10 | 0.662 | 0.628 | 0.584 | 0.624 | 0.032 | -| 20 | 0.612 | 0.640 | 0.619 | 0.624 | 0.012 | -| 30 | 0.635 | 0.635 | 0.679 | 0.650 | 0.021 | diff --git a/docs/original/baseline_results/cifar10_sleeper_agent_results.md b/docs/original/baseline_results/cifar10_sleeper_agent_results.md deleted file mode 100644 index 25c5ac7a6..000000000 --- a/docs/original/baseline_results/cifar10_sleeper_agent_results.md +++ /dev/null @@ -1,73 +0,0 @@ -# Cifar10 Sleeper Agent Baseline Evaluation - -Results obtained using Armory 0.16.4 - -### Undefended - -Mean of 3 runs - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.735 | 0.740 | - | - | -| 01 | 0.739 | 0.770 | 0.726 | 0.038 | -| 05 | 0.738 | 0.771 | 0.722 | 0.135 | -| 10 | 0.739 | 0.788 | 0.715 | 0.212 | -| 20 | 0.743 | 0.780 | 0.698 | 0.524 | -| 30 | 0.731 | 0.794 | 0.670 | 0.753 | - - -### Random Filter - -Mean of 3 runs - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.690 | 0.761 | - | - | -| 01 | 0.703 | 0.791 | 0.700 | 0.029 | -| 05 | 0.713 | 0.777 | 0.696 | 0.176 | -| 10 | 0.711 | 0.810 | 0.700 | 0.079 | -| 20 | 0.705 | 0.745 | 0.676 | 0.296 | -| 30 | 0.708 | 0.745 | 0.678 | 0.346 | - - -### Perfect Filter - -Mean of 3 runs - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.749 | 0.800 | - | - | -| 01 | 0.727 | 0.694 | 0.715 | 0.045 | -| 05 | 0.741 | 0.749 | 0.729 | 0.018 | -| 10 | 0.741 | 0.767 | 0.731 | 0.028 | -| 20 | 0.731 | 0.778 | 0.725 | 0.009 | -| 30 | 0.741 | 0.807 | 0.736 | 0.013 | - - -### Activation Clustering - -Mean of 3 runs - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.650 | 0.659 | - | - | -| 01 | 0.646 | 0.661 | 0.642 | 0.031 | -| 05 | 0.652 | 0.647 | 0.647 | 0.053 | -| 10 | 0.664 | 0.776 | 0.658 | 0.029 | -| 20 | 0.662 | 0.696 | 0.640 | 0.188 | -| 30 | 0.666 | 0.668 | 0.630 | 0.462 | - - -### Spectral Signatures - -Mean of 3 runs - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.684 | 0.738 | - | - | -| 01 | 0.675 | 0.768 | 0.671 | 0.044 | -| 05 | 0.668 | 0.660 | 0.656 | 0.098 | -| 10 | 0.676 | 0.694 | 0.664 | 0.131 | -| 20 | 0.661 | 0.709 | 0.632 | 0.356 | -| 30 | 0.656 | 0.729 | 0.625 | 0.387 | - diff --git a/docs/original/baseline_results/cifar10_witches_brew_results.md b/docs/original/baseline_results/cifar10_witches_brew_results.md deleted file mode 100644 index 13dd2985f..000000000 --- a/docs/original/baseline_results/cifar10_witches_brew_results.md +++ /dev/null @@ -1,146 +0,0 @@ -# Cifar10 Witches' Brew Baseline Evaluation - -Results obtained using Armory 0.15.X (July 2022) - -Note: the baseline CIFAR resnet was updated in Armory 0.16.1. - -## Undefended - -**Accuracy on Non-trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|--------------| -|0% |0.746446|0.747848|0.748448|0.7475806667|0.0008388886829| -|10% |0.743744|0.743544|0.739139|0.7421423333|0.002125246391| -|20% |0.735035|0.731532|0.74004|0.7355356667|0.003491371873| -|30% |0.750651|0.741842|0.736537|0.74301 |0.740463 | - -**Accuracy on Trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.7 |0.7 |0.8 |0.7333333333|0.04714045208| -|10% |0.2 |0.3 |0.4 |0.3 |0.08164965809| -|20% |0.1 |0.1 |0.1 |0.1 |0 | -|30% |0.3 |0.4 |0.3 |0.3333333333|0.04714045208| - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0 |0 |0 |0 |0 | -|10% |0.7 |0.5 |0.6 |0.6 |0.08164965809| -|20% |0.7 |0.8 |0.6 |0.7 |0.08164965809| -|30% |0.7 |0.6 |0.4 |0.5666666667|0.1247219129 | - - -## Perfect Filter - -**Accuracy on Non-trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.743944|0.738238|0.733934|0.7387053333|0.004099904498| -|10% |0.741041|0.741842|0.739339|0.7407406667|0.001043680134| -|20% |0.732232|0.733534|0.729229|0.731665 |0.001802659702| -|30% |0.727928|0.720921|0.726527|0.7251253333|0.003027431731| - -**Accuracy on Trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.5 |0.5 |0.5 |0.5 |0 | -|10% |0.7 |0.6 |0.5 |0.6 |0.08164965809| -|20% |0.6 |0.6 |0.6 |0.6 |0 | -|30% |0.5 |0.6 |0.5 |0.5333333333|0.04714045208| - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0 |0 |0.1 |0.03333333333|0.04714045208| -|10% |0.1 |0 |0 |0.03333333333|0.04714045208| -|20% |0 |0 |0 |0 |0 | -|30% |0 |0 |0 |0 |0 | - - -## Random Filter - -**Accuracy on Non-trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.728128|0.728128|0.708609|0.722523 |0.009201344841| -|10% |0.715716|0.714214|0.716717|0.715549 |0.001028646036| -|20% |0.702503|0.717417|0.700901|0.7069403333|0.007436935271| -|30% |0.703203|0.688488|0.696597|0.696096 |0.006017810067| - -**Accuracy on Trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.6 |0.6 |0.6 |0.6 |0 | -|10% |0.1 |0.2 |0.2 |0.1666666667|0.04714045208| -|20% |0 |0.1 |0 |0.03333333333|0.04714045208| -|30% |0.1 |0.1 |0.1 |0.1 |0 | - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.1 |0.1 |0.1 |0.1 |0 | -|10% |0.9 |0.7 |0.6 |0.7333333333|0.1247219129 | -|20% |0.8 |0.5 |0.8 |0.7 |0.1414213562 | -|30% |0.7 |0.7 |0.9 |0.7666666667|0.09428090416| - - - -## Activation Clustering - -**Accuracy on Non-trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.664665|0.658559|0.657257|0.6601603333|0.003229325764| -|10% |0.65966|0.660561|0.651451|0.657224 |0.004098666206| -|20% |0.667067|0.64004|0.643544|0.650217 |0.01200031608| -|30% |0.637037|0.630731|0.645846|0.6378713333|0.006198811194| - -**Accuracy on Trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.3 |0.4 |0.3 |0.3333333333|0.04714045208| -|10% |0.4 |0.2 |0.4 |0.3333333333|0.09428090416| -|20% |0.3 |0.1 |0 |0.1333333333|0.1247219129 | -|30% |0.1 |0.2 |0.2 |0.1666666667|0.04714045208| - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.1 |0 |0 |0.03333333333|0.04714045208| -|10% |0.6 |0.3 |0.5 |0.4666666667|0.1247219129 | -|20% |0.6 |0.7 |0.6 |0.6333333333|0.04714045208| -|30% |0.8 |0.8 |0.5 |0.7 |0.1414213562 | - - - -## Spectral Signatures - -**Accuracy on Non-trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.687487|0.683483|0.67958|0.6835166667|0.003228107013| -|10% |0.664765|0.667067|0.667568|0.6664666667|0.001220519653| -|20% |0.673373|0.655656|0.664064|0.6643643333|0.007236051978| -|30% |0.63994|0.657257|0.664064|0.6537536667|0.01015535499| - -**Accuracy on Trigger Images** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0.7 |0.6 |0.6 |0.6333333333|0.04714045208| -|10% |0.2 |0.2 |0.2 |0.2 |0 | -|20% |0 |0.1 |0.1 |0.06666666667|0.04714045208| -|30% |0 |0 |0.1 |0.03333333333|0.04714045208| - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0% |0 |0.1 |0 |0.03333333333|0.04714045208| -|10% |0.7 |0.5 |0.8 |0.6666666667|0.1247219129 | -|20% |0.6 |0.6 |0.6 |0.6 |0 | -|30% |0.6 |0.8 |0.3 |0.5666666667|0.2054804668 | - - - - - diff --git a/docs/original/baseline_results/dapricot_results.md b/docs/original/baseline_results/dapricot_results.md deleted file mode 100644 index ed1fbd233..000000000 --- a/docs/original/baseline_results/dapricot_results.md +++ /dev/null @@ -1,16 +0,0 @@ -# Dapricot Baseline Evaluation - -Results obtained using Armory v0.13.3 and [dev test data](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/data/adversarial/dapricot_test.py) - -| Attack | Patch Size | Target Success (Undefended) | Target mAP (Undefended) | Target Success (Defended) | Target mAP (Defended) | Test Size | -|---------------|------------|-----------------------------|-------------------------|---------------------------|-----------------------|-----------| -| Masked PGD | all | 0.99 | 0.91 | 0.99 | 0.91 | 100 | -| Masked PGD | small | 0.97 | 0.91 | 0.97 | 0.91 | 100 | -| Masked PGD | medium | 1.00 | 1.00 | 1.00 | 0.91 | 100 | -| Masked PGD | large | 1.00 | 1.00 | 1.00 | 0.91 | 100 | -| Robust DPatch | all | 0.56 | 0.64 | 0.61 | 0.64 | 100 | -| Robust DPatch | small | 0.51 | 0.64 | 0.60 | 0.64 | 100 | -| Robust DPatch | medium | 0.61 | 0.64 | 0.65 | 0.73 | 100 | -| Robust DPatch | large | 0.55 | 0.64 | 0.63 | 0.73 | 100 | - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/scenario_configs) \ No newline at end of file diff --git a/docs/original/baseline_results/gtsrb_clbd_results.md b/docs/original/baseline_results/gtsrb_clbd_results.md deleted file mode 100644 index 2ed257e3f..000000000 --- a/docs/original/baseline_results/gtsrb_clbd_results.md +++ /dev/null @@ -1,296 +0,0 @@ -# GTSRB Clean-label Backdoor Baseline Evaluation - -Results obtained using Armory ~0.14.X (March 2022) - -## Bullet Hole Trigger - -## Undefended - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.967 | 0.961 | 0.963 | 0.963 | 0.002 | -| 20 | 0.971 | 0.965 | 0.975 | 0.970 | 0.004 | -| 50 | 0.967 | 0.964 | 0.961 | 0.964 | 0.002 | -| 80 | 0.967 | 0.971 | 0.958 | 0.965 | 0.005 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.928 | 0.930 | 0.925 | 0.928 | 0.002 | -| 20 | 0.930 | 0.926 | 0.932 | 0.929 | 0.002 | -| 50 | 0.925 | 0.927 | 0.928 | 0.927 | 0.001 | -| 80 | 0.927 | 0.925 | 0.924 | 0.925 | 0.001 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.194 | 0.222 | 0.257 | 0.225 | 0.026 | -| 50 | 0.237 | 0.237 | 0.233 | 0.236 | 0.002 | -| 80 | 0.267 | 0.276 | 0.261 | 0.268 | 0.006 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.920 | 0.914 | 0.917 | 0.917 | 0.002 | -| 50 | 0.913 | 0.915 | 0.916 | 0.914 | 0.001 | -| 80 | 0.913 | 0.909 | 0.910 | 0.911 | 0.001 | - - -### Random Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.961 | 0.950 | 0.947 | 0.953 | 0.006 | -| 20 | 0.968 | 0.961 | 0.967 | 0.965 | 0.003 | -| 50 | 0.969 | 0.971 | 0.971 | 0.970 | 0.001 | -| 80 | 0.981 | 0.954 | 0.972 | 0.969 | 0.011 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.925 | 0.923 | 0.923 | 0.924 | 0.001 | -| 20 | 0.925 | 0.924 | 0.924 | 0.924 | 0.000 | -| 50 | 0.926 | 0.929 | 0.925 | 0.927 | 0.002 | -| 80 | 0.928 | 0.924 | 0.929 | 0.927 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.236 | 0.207 | 0.237 | 0.227 | 0.014 | -| 50 | 0.253 | 0.250 | 0.239 | 0.247 | 0.006 | -| 80 | 0.246 | 0.279 | 0.275 | 0.267 | 0.015 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.912 | 0.913 | 0.911 | 0.912 | 0.001 | -| 50 | 0.912 | 0.916 | 0.912 | 0.913 | 0.002 | -| 80 | 0.914 | 0.910 | 0.914 | 0.913 | 0.002 | - - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.915 | 0.886 | 0.842 | 0.881 | 0.030 | -| 20 | 0.906 | 0.897 | 0.912 | 0.905 | 0.006 | -| 50 | 0.894 | 0.849 | 0.861 | 0.868 | 0.019 | -| 80 | 0.904 | 0.910 | 0.907 | 0.907 | 0.002 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.871 | 0.866 | 0.861 | 0.866 | 0.004 | -| 20 | 0.873 | 0.879 | 0.874 | 0.875 | 0.003 | -| 50 | 0.854 | 0.858 | 0.865 | 0.859 | 0.004 | -| 80 | 0.866 | 0.861 | 0.854 | 0.860 | 0.005 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.197 | 0.292 | 0.256 | 0.248 | 0.039 | -| 50 | 0.303 | 0.265 | 0.282 | 0.283 | 0.015 | -| 80 | 0.250 | 0.260 | 0.272 | 0.261 | 0.009 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.866 | 0.867 | 0.862 | 0.865 | 0.002 | -| 50 | 0.841 | 0.849 | 0.855 | 0.848 | 0.005 | -| 80 | 0.854 | 0.849 | 0.842 | 0.848 | 0.005 | - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.965 | 0.963 | 0.963 | 0.963 | 0.001 | -| 20 | 0.968 | 0.964 | 0.958 | 0.963 | 0.004 | -| 50 | 0.963 | 0.969 | 0.961 | 0.964 | 0.004 | -| 80 | 0.971 | 0.971 | 0.969 | 0.970 | 0.001 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.928 | 0.929 | 0.925 | 0.928 | 0.002 | -| 20 | 0.927 | 0.929 | 0.926 | 0.927 | 0.001 | -| 50 | 0.926 | 0.929 | 0.927 | 0.927 | 0.001 | -| 80 | 0.929 | 0.929 | 0.927 | 0.928 | 0.001 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.126 | 0.097 | 0.133 | 0.119 | 0.016 | -| 50 | 0.092 | 0.082 | 0.147 | 0.107 | 0.029 | -| 80 | 0.126 | 0.118 | 0.100 | 0.115 | 0.011 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.920 | 0.923 | 0.918 | 0.920 | 0.002 | -| 50 | 0.919 | 0.921 | 0.919 | 0.920 | 0.001 | -| 80 | 0.922 | 0.919 | 0.920 | 0.920 | 0.001 | - - - -## Peace Sign Trigger - -### Undefended - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.968 | 0.964 | 0.972 | 0.968 | 0.003 | -| 20 | 0.971 | 0.964 | 0.975 | 0.970 | 0.005 | -| 50 | 0.964 | 0.956 | 0.969 | 0.963 | 0.006 | -| 80 | 0.964 | 0.972 | 0.965 | 0.967 | 0.004 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.930 | 0.927 | 0.926 | 0.928 | 0.002 | -| 20 | 0.932 | 0.934 | 0.932 | 0.933 | 0.001 | -| 50 | 0.926 | 0.926 | 0.929 | 0.927 | 0.002 | -| 80 | 0.929 | 0.928 | 0.928 | 0.928 | 0.000 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.676 | 0.560 | 0.597 | 0.611 | 0.049 | -| 50 | 0.547 | 0.533 | 0.660 | 0.580 | 0.057 | -| 80 | 0.643 | 0.649 | 0.679 | 0.657 | 0.016 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.893 | 0.900 | 0.898 | 0.897 | 0.003 | -| 50 | 0.895 | 0.896 | 0.892 | 0.895 | 0.002 | -| 80 | 0.893 | 0.891 | 0.888 | 0.891 | 0.002 | - - -### Random Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.964 | 0.958 | 0.956 | 0.959 | 0.003 | -| 20 | 0.960 | 0.963 | 0.965 | 0.963 | 0.002 | -| 50 | 0.957 | 0.958 | 0.967 | 0.961 | 0.004 | -| 80 | 0.969 | 0.961 | 0.965 | 0.965 | 0.003 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.919 | 0.924 | 0.924 | 0.922 | 0.002 | -| 20 | 0.924 | 0.926 | 0.924 | 0.925 | 0.001 | -| 50 | 0.924 | 0.926 | 0.922 | 0.924 | 0.002 | -| 80 | 0.927 | 0.922 | 0.924 | 0.924 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.637 | 0.653 | 0.624 | 0.638 | 0.012 | -| 50 | 0.611 | 0.581 | 0.656 | 0.616 | 0.031 | -| 80 | 0.622 | 0.646 | 0.710 | 0.659 | 0.037 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.885 | 0.887 | 0.887 | 0.886 | 0.001 | -| 50 | 0.890 | 0.894 | 0.885 | 0.889 | 0.004 | -| 80 | 0.891 | 0.885 | 0.885 | 0.887 | 0.003 | - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.907 | 0.929 | 0.914 | 0.917 | 0.009 | -| 20 | 0.858 | 0.897 | 0.889 | 0.881 | 0.017 | -| 50 | 0.914 | 0.910 | 0.929 | 0.918 | 0.008 | -| 80 | 0.858 | 0.926 | 0.892 | 0.892 | 0.028 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.861 | 0.871 | 0.872 | 0.868 | 0.005 | -| 20 | 0.865 | 0.852 | 0.870 | 0.862 | 0.008 | -| 50 | 0.871 | 0.865 | 0.871 | 0.869 | 0.003 | -| 80 | 0.856 | 0.861 | 0.860 | 0.859 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.579 | 0.685 | 0.621 | 0.628 | 0.043 | -| 50 | 0.660 | 0.607 | 0.675 | 0.647 | 0.029 | -| 80 | 0.671 | 0.722 | 0.700 | 0.698 | 0.021 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.838 | 0.816 | 0.838 | 0.831 | 0.011 | -| 50 | 0.838 | 0.833 | 0.835 | 0.836 | 0.002 | -| 80 | 0.823 | 0.823 | 0.825 | 0.824 | 0.001 | - - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.965 | 0.965 | 0.965 | 0.965 | 0.000 | -| 20 | 0.958 | 0.960 | 0.958 | 0.959 | 0.001 | -| 50 | 0.974 | 0.972 | 0.963 | 0.969 | 0.005 | -| 80 | 0.965 | 0.963 | 0.972 | 0.967 | 0.004 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | 0.929 | 0.928 | 0.929 | 0.929 | 0.000 | -| 20 | 0.926 | 0.925 | 0.929 | 0.927 | 0.002 | -| 50 | 0.926 | 0.926 | 0.928 | 0.927 | 0.001 | -| 80 | 0.926 | 0.927 | 0.927 | 0.927 | 0.000 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.222 | 0.214 | 0.151 | 0.196 | 0.032 | -| 50 | 0.047 | 0.064 | 0.057 | 0.056 | 0.007 | -| 80 | 0.253 | 0.272 | 0.118 | 0.214 | 0.069 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | run3 | mean | std | -|--------------|------|------|------|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.895 | 0.899 | 0.903 | 0.899 | 0.003 | -| 50 | 0.902 | 0.905 | 0.910 | 0.905 | 0.003 | -| 80 | 0.900 | 0.899 | 0.903 | 0.901 | 0.001 | - - - - - - - diff --git a/docs/original/baseline_results/gtsrb_dlbd_results.md b/docs/original/baseline_results/gtsrb_dlbd_results.md deleted file mode 100644 index 40963fe47..000000000 --- a/docs/original/baseline_results/gtsrb_dlbd_results.md +++ /dev/null @@ -1,348 +0,0 @@ -# GTSRB Dirty-label Backdoor Baseline Evaluation - -## Bullet Hole Trigger - -### Undefended - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0.000 | -|0.01 |0.287|0.288|0.261|0.279 |0.012 | -|0.05 |0.557|0.685|0.465|0.569 |0.090 | -|0.1 |0.839|0.821|0.801|0.820 |0.016 | -|0.2 |0.914|0.889|0.926|0.910 |0.015 | -|0.3 |0.928|0.951|0.940|0.940 |0.009 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.922|0.922|0.926|0.9233333333|0.002309401077| -|0.05 |0.909|0.906|0.895|0.9033333333|0.007371114796| -|0.1 |0.894|0.894|0.899|0.8956666667|0.002886751346| -|0.2 |0.89 |0.895|0.89 |0.8916666667|0.002886751346| -|0.3 |0.889|0.888|0.887|0.888 |0.001 | - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.983|0.975|0.922|0.960 |0.03315116891| -|0.01 |0.972|0.968|0.974|0.971 |0.003055050463| -|0.05 |0.971|0.963|0.949|0.961 |0.01113552873| -|0.1 |0.961|0.958|0.979|0.966 |0.01135781669| -|0.2 |0.965|0.958|0.949|0.957 |0.008020806277| -|0.3 |0.963|0.963|0.946|0.957 |0.009814954576| - - - -### Random Filter - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0 | -|0.01 |0.103|0.268|0.031|0.134 |0.1215030864 | -|0.05 |0.314|0.724|0.667|0.568 |0.2220953249 | -|0.1 |0.844|0.607|0.783|0.745 |0.1230623148 | -|0.2 |0.892|0.9 |0.607|0.800 |0.166902167 | -|0.3 |0.957|0.953|0.897|0.936 |0.03354598833| - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.904|0.918|0.863|0.895 |0.02858321186| -|0.05 |0.847|0.899|0.906|0.884 |0.03223352292| -|0.1 |0.893|0.888|0.9 |0.894 |0.006027713773| -|0.2 |0.888|0.883|0.845|0.872 |0.02351595203| -|0.3 |0.889|0.889|0.878|0.885 |0.006350852961| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.964|0.982|0.964|0.970 |0.008 | -|0.01 |0.944|0.971|0.925|0.947 |0.019 | -|0.05 |0.879|0.968|0.974|0.940 |0.043 | -|0.1 |0.972|0.94 |0.963|0.958 |0.013 | -|0.2 |0.964|0.954|0.814|0.911 |0.068 | -|0.3 |0.958|0.96 |0.936|0.951 |0.011 | - - - -### Activation Clustering - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0 | -|0.01 |0.267|0.322|0.278|0.289 |0.02910326442| -|0.05 |0.718|0.668|0.686|0.691 |0.02532455988| -|0.1 |0.835|0.856|0.756|0.816 |0.05272886622| -|0.2 |0.919|0.668|0.925|0.837 |0.1466776511 | -|0.3 |0.919|0.918|0.653|0.830 |0.1532873119 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.912|0.914|0.911|0.912 |0.001527525232| -|0.05 |0.887|0.892|0.896|0.892 |0.004509249753| -|0.1 |0.889|0.892|0.88 |0.887 |0.006244997998| -|0.2 |0.873|0.846|0.88 |0.866 |0.01795364401| -|0.3 |0.875|0.888|0.825|0.863 |0.03326158946| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.974|0.976|0.868|0.939 |0.050 | -|0.01 |0.929|0.978|0.969|0.959 |0.021 | -|0.05 |0.965|0.94 |0.958|0.954 |0.011 | -|0.1 |0.953|0.963|0.931|0.949 |0.013 | -|0.2 |0.96 |0.858|0.958|0.925 |0.048 | -|0.3 |0.969|0.956|0.749|0.891 |0.101 | - - - -### Perfect Filter - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0 | -|0.01 |0.025|0.185|0.1 |0.103 |0.08005206639| -|0.05 |0.146|0.026|0.111|0.094 |0.06171169527| -|0.1 |0.138|0.082|0.057|0.092 |0.0414769012 | -|0.2 |0.135|0.124|0.146|0.135 |0.011 | -|0.3 |0.16 |0.165|0.081|0.135 |0.04712041313| - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.873|0.93 |0.934|0.912 |0.03412232896| -|0.05 |0.926|0.876|0.934|0.912 |0.03143246729| -|0.1 |0.938|0.917|0.918|0.924 |0.0118462371 | -|0.2 |0.935|0.928|0.933|0.932 |0.003605551275| -|0.3 |0.931|0.931|0.938|0.933 |0.004041451884| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.979|0.974|0.982|0.978 |0.003 | -|0.01 |0.919|0.981|0.975|0.958 |0.028 | -|0.05 |0.976|0.892|0.972|0.947 |0.039 | -|0.1 |0.976|0.956|0.961|0.964 |0.008 | -|0.2 |0.978|0.972|0.981|0.977 |0.004 | -|0.3 |0.969|0.974|0.979|0.974 |0.004 | - - - -### Spectral Signatures - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |0.000 | | -|0.01 | | | |0.268 | | -|0.05 | | | |0.562 | | -|0.1 | | | |0.819 | | -|0.2 | | | |0.823 | | -|0.3 | | | |0.915 | | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |- | | -|0.01 | | | |0.9261810504| | -|0.05 | | | |0.9002639219| | -|0.1 | | | |0.8919503827| | -|0.2 | | | |0.8726576933| | -|0.3 | | | |0.8911850092| | - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |0.970 | | -|0.01 | | | |0.965 | | -|0.05 | | | |0.960 | | -|0.1 | | | |0.959 | | -|0.2 | | | |0.920 | | -|0.3 | | | |0.944 | | - - - - - - - - -## Peace Sign Trigger - -### Undefended - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0.000 | -|0.01 |0.590|0.772|0.868|0.743 |0.115 | -|0.05 |0.950|0.978|0.932|0.953 |0.019 | -|0.1 |0.981|0.986|0.982|0.983 |0.002 | -|0.2 |0.930|0.992|0.979|0.967 |0.027 | -|0.3 |0.999|0.996|0.999|0.998 |0.001 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.901|0.897|0.89 |0.896 |0.005567764363| -|0.05 |0.89 |0.891|0.893|0.8913333333|0.001527525232| -|0.1 |0.886|0.885|0.888|0.8863333333|0.001527525232| -|0.2 |0.861|0.887|0.87 |0.8726666667|0.01320353488| -|0.3 |0.887|0.887|0.885|0.8863333333|0.001154700538| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.975|0.942|0.965|0.961 |0.01692138686| -|0.01 |0.972|0.981|0.969|0.974 |0.006244997998| -|0.05 |0.979|0.974|0.983|0.979 |0.004509249753| -|0.1 |0.978|0.969|0.982|0.976 |0.006658328118| -|0.2 |0.924|0.969|0.951|0.948 |0.02264950331| -|0.3 |0.967|0.971|0.971|0.970 |0.002309401077| - - - -### Random Filter - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0.000 | -|0.01 |0.689|0.746|0.569|0.668 |0.074 | -|0.05 |0.951|0.956|0.351|0.753 |0.284 | -|0.1 |0.985|0.967|0.985|0.979 |0.008 | -|0.2 |0.872|0.354|0.988|0.738 |0.276 | -|0.3 |1 |0.997|0.996|0.998 |0.002 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.903|0.897|0.886|0.895 |0.008621678104| -|0.05 |0.889|0.89 |0.87 |0.883 |0.01126942767| -|0.1 |0.884|0.888|0.89 |0.887 |0.003055050463| -|0.2 |0.82 |0.858|0.889|0.856 |0.03455912808| -|0.3 |0.844|0.885|0.885|0.871 |0.02367136104| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.929|0.965|0.912|0.935 |0.02706165799| -|0.01 |0.975|0.975|0.949|0.966 |0.015011107 | -|0.05 |0.982|0.968|0.925|0.958 |0.02970409624| -|0.1 |0.965|0.967|0.978|0.970 |0.007 | -|0.2 |0.828|0.824|0.982|0.878 |0.09008884504| -|0.3 |0.9 |0.968|0.975|0.948 |0.04142865353| - - - -### Activation Clustering - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0.000 | -|0.01 |0.644|0.483|0.364|0.497 |0.115 | -|0.05 |0.938|0.947|0.772|0.886 |0.080 | -|0.1 |0.974|0.979|0.978|0.977 |0.002 | -|0.2 |0.979|0.988|0.989|0.985 |0.004 | -|0.3 |1 |0.996|0.969|0.988 |0.014 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.893|0.866|0.781|0.847 |0.05844940832| -|0.05 |0.876|0.882|0.864|0.874 |0.00916515139| -|0.1 |0.88 |0.882|0.874|0.879 |0.004163331999| -|0.2 |0.878|0.879|0.877|0.878 |0.001 | -|0.3 |0.873|0.882|0.848|0.868 |0.01761628035| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.971|0.969|0.964|0.968 |0.003 | -|0.01 |0.975|0.94 |0.968|0.961 |0.015 | -|0.05 |0.974|0.965|0.933|0.957 |0.018 | -|0.1 |0.965|0.969|0.938|0.957 |0.014 | -|0.2 |0.969|0.968|0.978|0.972 |0.004 | -|0.3 |0.904|0.963|0.899|0.922 |0.029 | - - - -### Perfect Filter - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.000|0.000|0.000|0.000 |0.000 | -|0.01 |0.032|0.221|0.158|0.137 |0.079 | -|0.05 |0.076|0.019|0.039|0.045 |0.024 | -|0.1 |0.024|0.157|0.036|0.072 |0.060 | -|0.2 |0.35 |0.138|0.196|0.228 |0.089 | -|0.3 |0.189|0.074|0.097|0.120 |0.050 | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |- |- |- |- |- | -|0.01 |0.921|0.91 |0.911|0.914 |0.00608276253| -|0.05 |0.848|0.881|0.925|0.885 |0.03863073043| -|0.1 |0.906|0.854|0.922|0.894 |0.03555277767| -|0.2 |0.914|0.917|0.909|0.913 |0.004041451884| -|0.3 |0.91 |0.92 |0.911|0.914 |0.005507570547| - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 |0.979|0.986|0.981|0.982 |0.003 | -|0.01 |0.981|0.982|0.974|0.979 |0.004 | -|0.05 |0.881|0.907|0.972|0.920 |0.038 | -|0.1 |0.979|0.904|0.967|0.950 |0.033 | -|0.2 |0.968|0.981|0.971|0.973 |0.006 | -|0.3 |0.971|0.972|0.958|0.967 |0.006 | - - - -### Spectral Signatures - -**Attack Success Rate** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |0.000 | | -|0.01 | | | |0.270 | | -|0.05 | | | |0.774 | | -|0.1 | | | |0.756 | | -|0.2 | | | |0.983 | | -|0.3 | | | |0.992 | | - -**Accuracy on Poisoned Test Data All Classes** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |- | | -|0.01 | | | |0.8585114806| | -|0.05 | | | |0.8861177092| | -|0.1 | | | |0.8614410135| | -|0.2 | | | |0.8864080232| | -|0.3 | | | |0.8678807073| | - -**Accuracy on Benign Test Data Source Class** -|Poison Ratio |Run 1|Run 2|Run 3|Mean |Std | -|-------------------|-----|-----|-----|------------|-------------| -|0 | | | |0.972 | | -|0.01 | | | |0.921 | | -|0.05 | | | |0.949 | | -|0.1 | | | |0.913 | | -|0.2 | | | |0.966 | | -|0.3 | | | |0.944 | | diff --git a/docs/original/baseline_results/gtsrb_witches_brew_results.md b/docs/original/baseline_results/gtsrb_witches_brew_results.md deleted file mode 100644 index a4b83d85e..000000000 --- a/docs/original/baseline_results/gtsrb_witches_brew_results.md +++ /dev/null @@ -1,3 +0,0 @@ -# GTSRB Witches' Brew Baseline Evaluation - -Coming soon \ No newline at end of file diff --git a/docs/original/baseline_results/librispeech_asr_results.md b/docs/original/baseline_results/librispeech_asr_results.md deleted file mode 100644 index bf830f08e..000000000 --- a/docs/original/baseline_results/librispeech_asr_results.md +++ /dev/null @@ -1,49 +0,0 @@ -# Audio ASR Baseline Evaluation: - - -## Deep Speech 2 - -Table 1 (Results obtained using Armory v0.13.3) - -| Attack | Targeted | Budget | Benign WER (Undefended) | Adversarial WER (Undefended) | Benign WER (Defended) | Adversarial WER (Defended) | Test Size | -|--------------------------|----------|----------------|-------------------------|------------------------------|-----------------------|----------------------------|-----------| -| Imperceptible ASR | yes | max_iter_1=100 | 0.10 | 0.63 | 0.13 | N/A* | 320 | -| Imperceptible ASR | yes | max_iter_1=200 | 0.10 | 0.20 | 0.13 | N/A | 320 | -| Imperceptible ASR | yes | max_iter_1=400 | 0.10 | 0.11 | 0.13 | N/A | 320 | -| Kenansville | no | snr=20dB | 0.10 | 0.27 | 0.13 | 0.36 | 1000 | -| Kenansville | no | snr=30dB | 0.10 | 0.11 | 0.13 | 0.17 | 1000 | -| Kenansville | no | snr=40dB | 0.10 | 0.10 | 0.13 | 0.13 | 1000 | -| PGD (single channel) | no | snr=20dB | 0.10 | 0.46 | 0.13 | 0.53 | 100 | -| PGD (single channel) | no | snr=30dB | 0.10 | 0.46 | 0.13 | 0.50 | 100 | -| PGD (single channel) | no | snr=40dB | 0.10 | 0.33 | 0.13 | 0.36 | 100 | -| PGD (single channel)* | yes | snr=20dB | 0.11 | 1.03 | 0.15 | 1.01 | 100 | -| PGD (single channel)* | yes | snr=30dB | 0.11 | 1.02 | 0.15 | 0.99 | 100 | -| PGD (single channel)* | yes | snr=40dB | 0.11 | 0.88 | 0.15 | 0.84 | 100 | -| PGD (multiple channels) | no | snr=20dB | 0.13 | 0.96 | N/A | N/A | 100 | -| PGD (multiple channels) | no | snr=30dB | 0.13 | 0.59 | N/A | N/A | 100 | -| PGD (multiple channels) | no | snr=40dB | 0.13 | 0.38 | N/A | N/A | 100 | -| PGD (multiple channels)* | yes | snr=20dB | 0.13 | 0.99 | N/A | N/A | 100 | -| PGD (multiple channels)* | yes | snr=30dB | 0.13 | 0.92 | N/A | N/A | 100 | -| PGD (multiple channels)* | yes | snr=40dB | 0.13 | 0.75 | N/A | N/A | 100 | - -* \*Targeted attack, where a random target phrase of similar length as the ground truth, was applied but WER wrt the ground truth was calculated - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/scenario_configs) -* Missing defended baseline is due to current incompatibility of the attack and defense. - -Table 2 (Results are obtained using Armory v0.15.2) - -| Attack | Targeted | Budget | Attack Parameters | Entailment/Contradiction/Neutral Rates (Benign Undefended) | Number of Entailment/Contradiction/Neutral Rates (Adversarial Undefended) | Entailment/Contradiction/Neutral Rates (Benign Defended) | Entailment/Contradiction/Neutral Rates (Adversarial Defended) | Test Size | -|:------:|:--------:|:--------:|:---------------------------:|:----------------------------------------------------------:|:-------------------------------------------------------------------------:|:--------------------------------------------------------:|:-------------------------------------------------------------:|:---------:| -| PGD* | yes | snr=20dB | eps_step=0.05, max_iter=500 | 0.95/0.05/0.00 | 0.01/0.98/0.01 | 0.93/0.07/0.00 | 0.02/0.96/0.02 | 100 | -| PGD* | yes | snr=30dB | eps_step=0.03, max_iter=500 | 0.95/0.05/0.00 | 0.04/0.95/0.01 | 0.93/0.07/0.00 | 0.19/0.79/0.02 | 100 | -| PGD* | yes | snr=40dB | eps_step=0.01, max_iter=500 | 0.95/0.05/0.00 | 0.43/0.53/0.04 | 0.93/0.07/0.00 | 0.66/0.34/0.00 | 100 | - -* \*Targeted attack, where contradictory target phrases are generated from ground truth phrases by changing a few key words (e.g., target phrase: `he is a bad person`; ground truth phrase: `he is a good person`) - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/master/scenario_configs/eval5/asr_librispeech) - - -## HuBERT - -Coming soon \ No newline at end of file diff --git a/docs/original/baseline_results/librispeech_audio_classification_results.md b/docs/original/baseline_results/librispeech_audio_classification_results.md deleted file mode 100644 index 008bd6f19..000000000 --- a/docs/original/baseline_results/librispeech_audio_classification_results.md +++ /dev/null @@ -1,3 +0,0 @@ -# LibriSpeech Audio Classification Baseline Evaluation - -Coming soon \ No newline at end of file diff --git a/docs/original/baseline_results/resisc45_results.md b/docs/original/baseline_results/resisc45_results.md deleted file mode 100644 index c826b11e5..000000000 --- a/docs/original/baseline_results/resisc45_results.md +++ /dev/null @@ -1,14 +0,0 @@ -# RESISC-45 Image Classification Baseline Evaluation - -* **Baseline Model Performance: (results obtained using Armory < v0.10)** - * Baseline Clean Top-1 Accuracy: 93% - * Baseline Attacked (Universal Perturbation) Top-1 Accuracy: 6% - * Baseline Attacked (Universal Patch) Top-1 Accuracy: 23% -* **Baseline Defense Performance: (results obtained using Armory < v0.10)** -Baseline defense is art_experimental.defences.JpegCompressionNormalized(clip_values=(0.0, 1.0), quality=50, channel_index=3, apply_fit=False, -apply_predict=True, means=[0.36386173189316956, 0.38118692953271804, 0.33867067558870334], stds=[0.20350874, 0.18531173, 0.18472934]) - see -resisc45_baseline_densenet121_adversarial.json for example usage. -Baseline defense performance is evaluated for a grey-box attack: adversarial examples generated on undefended baseline model evaluated on defended model. - * Baseline Clean Top-1 Accuracy: 92% - * Baseline Attacked (Universal Perturbation) Top-1 Accuracy: 40% - * Baseline Attacked (Universal Patch) Top-1 Accuracy: 21% \ No newline at end of file diff --git a/docs/original/baseline_results/resisc_clbd_results.md b/docs/original/baseline_results/resisc_clbd_results.md deleted file mode 100644 index 4cd8d27af..000000000 --- a/docs/original/baseline_results/resisc_clbd_results.md +++ /dev/null @@ -1,147 +0,0 @@ -# RESISC-10 Clean-label Backdoor Baseline Evaluation - -## Letter A Trigger - -### Undefended - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.350 | 0.400 | 0.460 | 0.403 | 0.045 | -| 20 | 0.330 | 0.350 | 0.400 | 0.360 | 0.029 | -| 50 | 0.310 | 0.190 | 0.450 | 0.317 | 0.106 | -| 80 | 0.440 | 0.460 | 0.340 | 0.413 | 0.052 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.428 | 0.467 | 0.454 | 0.450 | 0.016 | -| 20 | 0.464 | 0.431 | 0.447 | 0.447 | 0.013 | -| 50 | 0.388 | 0.390 | 0.468 | 0.415 | 0.037 | -| 80 | 0.452 | 0.444 | 0.379 | 0.425 | 0.033 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.210 | 0.330 | 0.330 | 0.290 | 0.057 | -| 50 | 0.490 | 0.620 | 0.730 | 0.613 | 0.098 | -| 80 | 0.660 | 0.760 | 0.810 | 0.743 | 0.062 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.465 | 0.431 | 0.440 | 0.445 | 0.014 | -| 50 | 0.375 | 0.388 | 0.434 | 0.399 | 0.025 | -| 80 | 0.421 | 0.417 | 0.356 | 0.398 | 0.030 | - - -### Random Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.300 | 0.330 | 0.280 | 0.303 | 0.021 | -| 20 | 0.350 | 0.360 | 0.390 | 0.367 | 0.017 | -| 50 | 0.300 | 0.480 | 0.240 | 0.340 | 0.102 | -| 80 | 0.560 | 0.400 | 0.400 | 0.453 | 0.075 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.459 | 0.412 | 0.378 | 0.416 | 0.033 | -| 20 | 0.482 | 0.401 | 0.352 | 0.412 | 0.054 | -| 50 | 0.429 | 0.399 | 0.393 | 0.407 | 0.016 | -| 80 | 0.430 | 0.449 | 0.480 | 0.453 | 0.021 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.270 | 0.220 | 0.150 | 0.213 | 0.049 | -| 50 | 0.430 | 0.640 | 0.600 | 0.557 | 0.091 | -| 80 | 0.730 | 0.690 | 0.810 | 0.743 | 0.050 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.481 | 0.398 | 0.351 | 0.410 | 0.054 | -| 50 | 0.426 | 0.367 | 0.374 | 0.389 | 0.026 | -| 80 | 0.390 | 0.422 | 0.452 | 0.421 | 0.025 | - - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.270 | 0.310 | 0.320 | 0.300 | 0.022 | -| 20 | 0.050 | 0.380 | 0.320 | 0.250 | 0.144 | -| 50 | 0.250 | 0.240 | 0.310 | 0.267 | 0.031 | -| 80 | 0.120 | 0.360 | 0.390 | 0.290 | 0.121 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.338 | 0.336 | 0.414 | 0.363 | 0.036 | -| 20 | 0.328 | 0.345 | 0.350 | 0.341 | 0.009 | -| 50 | 0.360 | 0.300 | 0.339 | 0.333 | 0.025 | -| 80 | 0.315 | 0.343 | 0.396 | 0.351 | 0.034 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.400 | 0.170 | 0.210 | 0.260 | 0.100 | -| 50 | 0.640 | 0.310 | 0.280 | 0.410 | 0.163 | -| 80 | 0.800 | 0.600 | 0.200 | 0.533 | 0.249 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.333 | 0.348 | 0.355 | 0.345 | 0.009 | -| 50 | 0.351 | 0.293 | 0.347 | 0.330 | 0.026 | -| 80 | 0.310 | 0.326 | 0.390 | 0.342 | 0.035 | - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.300 | 0.510 | 0.180 | 0.330 | 0.136 | -| 20 | 0.340 | 0.410 | 0.510 | 0.420 | 0.070 | -| 50 | 0.440 | 0.520 | 0.420 | 0.460 | 0.043 | -| 80 | 0.400 | 0.500 | 0.380 | 0.427 | 0.052 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | 0.403 | 0.490 | 0.343 | 0.412 | 0.060 | -| 20 | 0.406 | 0.427 | 0.437 | 0.423 | 0.013 | -| 50 | 0.497 | 0.474 | 0.428 | 0.466 | 0.029 | -| 80 | 0.448 | 0.428 | 0.418 | 0.431 | 0.012 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.050 | 0.130 | 0.050 | 0.077 | 0.038 | -| 50 | 0.110 | 0.060 | 0.080 | 0.083 | 0.021 | -| 80 | 0.080 | 0.060 | 0.050 | 0.063 | 0.012 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 |run3 | mean | std | -|--------------|------|------|-----|------|-----| -| 0 | - |- |- |- |- | -| 20 | 0.405 | 0.421 | 0.432 | 0.419 | 0.011 | -| 50 | 0.497 | 0.477 | 0.421 | 0.465 | 0.032 | -| 80 | 0.451 | 0.426 | 0.421 | 0.433 | 0.013 | - - - - diff --git a/docs/original/baseline_results/resisc_dlbd_results.md b/docs/original/baseline_results/resisc_dlbd_results.md deleted file mode 100644 index 13dbdd353..000000000 --- a/docs/original/baseline_results/resisc_dlbd_results.md +++ /dev/null @@ -1,165 +0,0 @@ -# RESISC-10 Dirty-label Backdoor Baseline Evaluation - -## Letter A Trigger - -### Undefended - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.680 | 0.610 | 0.645 | 0.035 | -| 05 | 0.680 | 0.640 | 0.660 | 0.020 | -| 10 | 0.550 | 0.630 | 0.590 | 0.040 | -| 20 | 0.550 | 0.590 | 0.570 | 0.020 | -| 30 | 0.520 | 0.700 | 0.610 | 0.090 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.813 | 0.763 | 0.788 | 0.025 | -| 05 | 0.793 | 0.772 | 0.782 | 0.011 | -| 10 | 0.779 | 0.769 | 0.774 | 0.005 | -| 20 | 0.761 | 0.779 | 0.770 | 0.009 | -| 30 | 0.750 | 0.781 | 0.766 | 0.016 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.170 | 0.150 | 0.160 | 0.010 | -| 05 | 0.120 | 0.220 | 0.170 | 0.050 | -| 10 | 0.230 | 0.360 | 0.295 | 0.065 | -| 20 | 0.340 | 0.610 | 0.475 | 0.135 | -| 30 | 0.790 | 0.680 | 0.735 | 0.055 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.810 | 0.759 | 0.784 | 0.026 | -| 05 | 0.790 | 0.766 | 0.778 | 0.012 | -| 10 | 0.776 | 0.756 | 0.766 | 0.010 | -| 20 | 0.752 | 0.745 | 0.748 | 0.004 | -| 30 | 0.707 | 0.728 | 0.718 | 0.011 | - - - -### Random Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.610 | 0.680 | 0.645 | 0.035 | -| 05 | 0.580 | 0.620 | 0.600 | 0.020 | -| 10 | 0.630 | 0.670 | 0.650 | 0.020 | -| 20 | 0.560 | 0.620 | 0.590 | 0.030 | -| 30 | 0.510 | 0.420 | 0.465 | 0.045 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.744 | 0.797 | 0.770 | 0.027 | -| 05 | 0.756 | 0.761 | 0.758 | 0.003 | -| 10 | 0.789 | 0.785 | 0.787 | 0.002 | -| 20 | 0.781 | 0.762 | 0.772 | 0.010 | -| 30 | 0.749 | 0.746 | 0.748 | 0.002 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.180 | 0.130 | 0.155 | 0.025 | -| 05 | 0.260 | 0.200 | 0.230 | 0.030 | -| 10 | 0.220 | 0.540 | 0.380 | 0.160 | -| 20 | 0.700 | 0.350 | 0.525 | 0.175 | -| 30 | 0.800 | 0.720 | 0.760 | 0.040 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.743 | 0.797 | 0.770 | 0.027 | -| 05 | 0.750 | 0.759 | 0.754 | 0.005 | -| 10 | 0.783 | 0.746 | 0.764 | 0.019 | -| 20 | 0.738 | 0.745 | 0.742 | 0.004 | -| 30 | 0.704 | 0.715 | 0.710 | 0.006 | - - - -### Activation Clustering - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.530 | 0.530 | 0.530 | 0.000 | -| 05 | 0.560 | 0.570 | 0.565 | 0.005 | -| 10 | 0.580 | 0.290 | 0.435 | 0.145 | -| 20 | 0.510 | 0.660 | 0.585 | 0.075 | -| 30 | 0.520 | 0.400 | 0.460 | 0.060 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.681 | 0.722 | 0.702 | 0.020 | -| 05 | 0.677 | 0.705 | 0.691 | 0.014 | -| 10 | 0.710 | 0.565 | 0.637 | 0.073 | -| 20 | 0.735 | 0.673 | 0.704 | 0.031 | -| 30 | 0.670 | 0.687 | 0.679 | 0.009 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.150 | 0.210 | 0.180 | 0.030 | -| 05 | 0.100 | 0.180 | 0.140 | 0.040 | -| 10 | 0.190 | 0.520 | 0.355 | 0.165 | -| 20 | 0.320 | 0.100 | 0.210 | 0.110 | -| 30 | 0.220 | 0.450 | 0.335 | 0.115 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.681 | 0.720 | 0.701 | 0.019 | -| 05 | 0.677 | 0.705 | 0.691 | 0.014 | -| 10 | 0.707 | 0.563 | 0.635 | 0.072 | -| 20 | 0.723 | 0.669 | 0.696 | 0.027 | -| 30 | 0.667 | 0.677 | 0.672 | 0.005 | - - - -### Perfect Filter - -**Accuracy on Benign Test Data Source Class** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.660 | 0.710 | 0.685 | 0.025 | -| 05 | 0.630 | 0.670 | 0.650 | 0.020 | -| 10 | 0.600 | 0.610 | 0.605 | 0.005 | -| 20 | 0.640 | 0.650 | 0.645 | 0.005 | -| 30 | 0.630 | 0.540 | 0.585 | 0.045 | - -**Accuracy on Benign Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.798 | 0.756 | 0.777 | 0.021 | -| 05 | 0.756 | 0.792 | 0.774 | 0.018 | -| 10 | 0.779 | 0.792 | 0.786 | 0.007 | -| 20 | 0.772 | 0.793 | 0.782 | 0.011 | -| 30 | 0.794 | 0.770 | 0.782 | 0.012 | - -**Attack Success Rate** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.130 | 0.100 | 0.115 | 0.015 | -| 05 | 0.200 | 0.070 | 0.135 | 0.065 | -| 10 | 0.220 | 0.150 | 0.185 | 0.035 | -| 20 | 0.210 | 0.140 | 0.175 | 0.035 | -| 30 | 0.120 | 0.200 | 0.160 | 0.040 | - -**Accuracy on Poisoned Test Data All Classes** -| Poison Ratio | run1 | run2 | mean | std | -|--------------|------|------|------|-----| -| 01 | 0.798 | 0.754 | 0.776 | 0.022 | -| 05 | 0.755 | 0.789 | 0.772 | 0.017 | -| 10 | 0.778 | 0.792 | 0.785 | 0.007 | -| 20 | 0.770 | 0.791 | 0.780 | 0.011 | -| 30 | 0.793 | 0.769 | 0.781 | 0.012 | - - - - diff --git a/docs/original/baseline_results/so2sat_results.md b/docs/original/baseline_results/so2sat_results.md deleted file mode 100644 index 001b5a079..000000000 --- a/docs/original/baseline_results/so2sat_results.md +++ /dev/null @@ -1,14 +0,0 @@ -# So2Sat Multimodal Image Classification Baseline Evaluation - -Results obtained using Armory v0.13.3 - -| Attacked Modality | Patch Ratio | Benign Accuracy (Undefended) | Adversarial Accuracy (Undefended) | Benign Accuracy (Defended) | Adversarial Accuracy (Defended) | Test Size | -|-------------------|-------------|------------------------------|-----------------------------------|----------------------------|---------------------------------|-----------| -| EO | 0.05 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | -| EO | 0.10 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | -| EO | 0.15 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | -| SAR | 0.05 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | -| SAR | 0.10 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | -| SAR | 0.15 | 0.583 | 0.00 | 0.556 | 0.00 | 1000 | - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/scenario_configs) diff --git a/docs/original/baseline_results/speech_commands_poison_results.md b/docs/original/baseline_results/speech_commands_poison_results.md deleted file mode 100644 index 277b1a6a0..000000000 --- a/docs/original/baseline_results/speech_commands_poison_results.md +++ /dev/null @@ -1,280 +0,0 @@ -# Speech Commands Dirty-label Backdoor Baseline Evaluation - -**All tables are the mean of 3 runs.** Results obtained with Armory 0.16.1 December 2022. - -Source class: 11 - -Target class: 2 - -Note: Because the source class has about 54K examples compared to the 1-3K in the other classes, -we evaluate with lower poison percentages compared to other poison evaluations on more balanced datasets. After 0 poison, the lowest fraction of poison we test is 0.1%. - -## Whistle Trigger - -### Undefended - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.928 | 0.989 | - | - | -| 0.1 | 0.942 | 0.989 | 0.873 | 0.839 | -| 0.5 | 0.935 | 0.989 | 0.858 | 0.937 | -| 01 | 0.941 | 0.981 | 0.861 | 0.975 | -| 05 | 0.938 | 0.982 | 0.857 | 0.988 | -| 10 | 0.937 | 0.979 | 0.855 | 0.996 | -| 20 | 0.940 | 0.975 | 0.859 | 0.993 | -| 30 | 0.937 | 0.980 | 0.856 | 0.995 | - - -### Random Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.925 | 0.984 | - | - | -| 0.1 | 0.928 | 0.983 | 0.867 | 0.755 | -| 0.5 | 0.928 | 0.980 | 0.852 | 0.931 | -| 01 | 0.931 | 0.977 | 0.853 | 0.955 | -| 05 | 0.937 | 0.980 | 0.856 | 0.986 | -| 10 | 0.928 | 0.971 | 0.848 | 0.993 | -| 20 | 0.934 | 0.978 | 0.853 | 0.994 | -| 30 | 0.923 | 0.988 | 0.841 | 0.994 | - - -### Perfect Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.936 | 0.977 | - | - | -| 0.1 | 0.938 | 0.986 | 0.938 | 0.003 | -| 0.5 | 0.933 | 0.979 | 0.933 | 0.001 | -| 01 | 0.944 | 0.986 | 0.944 | 0.003 | -| 05 | 0.945 | 0.984 | 0.945 | 0.002 | -| 10 | 0.944 | 0.984 | 0.943 | 0.006 | -| 20 | 0.937 | 0.980 | 0.937 | 0.001 | -| 30 | 0.937 | 0.976 | 0.937 | 0.008 | - - -### Activation Clustering - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.931 | 0.971 | - | - | -| 0.1 | 0.936 | 0.971 | 0.874 | 0.766 | -| 0.5 | 0.936 | 0.986 | 0.857 | 0.960 | -| 01 | 0.934 | 0.972 | 0.854 | 0.982 | -| 05 | 0.939 | 0.986 | 0.858 | 0.987 | -| 10 | 0.942 | 0.986 | 0.860 | 0.992 | -| 20 | 0.937 | 0.988 | 0.855 | 0.995 | -| 30 | 0.949 | 0.980 | 0.868 | 0.994 | - - -### Spectral Signatures - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.925 | 0.990 | - | - | -| 0.1 | 0.931 | 0.967 | 0.931 | 0.012 | -| 0.5 | 0.938 | 0.980 | 0.913 | 0.310 | -| 01 | 0.844 | 0.982 | 0.815 | 0.328 | -| 05 | 0.933 | 0.979 | 0.898 | 0.417 | -| 10 | 0.913 | 0.977 | 0.906 | 0.087 | -| 20 | 0.934 | 0.982 | 0.865 | 0.850 | -| 30 | 0.925 | 0.982 | 0.871 | 0.662 | - - - -## Clapping Trigger - -### Undefended - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.937 | 0.983 | - | - | -| 0.1 | 0.942 | 0.984 | 0.868 | 0.905 | -| 0.5 | 0.937 | 0.989 | 0.857 | 0.973 | -| 01 | 0.922 | 0.982 | 0.842 | 0.983 | -| 05 | 0.943 | 0.989 | 0.860 | 0.995 | -| 10 | 0.932 | 0.977 | 0.851 | 0.997 | -| 20 | 0.944 | 0.983 | 0.862 | 0.999 | -| 30 | 0.942 | 0.983 | 0.860 | 0.999 | - - -### Random Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.936 | 0.983 | - | - | -| 0.1 | 0.932 | 0.982 | 0.871 | 0.745 | -| 0.5 | 0.929 | 0.989 | 0.849 | 0.970 | -| 01 | 0.919 | 0.980 | 0.840 | 0.963 | -| 05 | 0.921 | 0.981 | 0.839 | 0.995 | -| 10 | 0.948 | 0.985 | 0.866 | 0.992 | -| 20 | 0.940 | 0.974 | 0.859 | 0.996 | -| 30 | 0.934 | 0.985 | 0.852 | 0.998 | - - -### Perfect Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.932 | 0.985 | - | - | -| 0.1 | 0.936 | 0.961 | 0.936 | 0.011 | -| 0.5 | 0.940 | 0.980 | 0.939 | 0.002 | -| 01 | 0.937 | 0.971 | 0.936 | 0.008 | -| 05 | 0.933 | 0.982 | 0.933 | 0.006 | -| 10 | 0.941 | 0.981 | 0.941 | 0.001 | -| 20 | 0.937 | 0.975 | 0.937 | 0.004 | -| 30 | 0.937 | 0.981 | 0.937 | 0.002 | - - -### Activation Clustering - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.934 | 0.979 | - | - | -| 0.1 | 0.889 | 0.922 | 0.819 | 0.900 | -| 0.5 | 0.941 | 0.985 | 0.863 | 0.952 | -| 01 | 0.933 | 0.988 | 0.852 | 0.984 | -| 05 | 0.932 | 0.983 | 0.851 | 0.991 | -| 10 | 0.940 | 0.987 | 0.858 | 0.998 | -| 20 | 0.938 | 0.983 | 0.856 | 0.998 | -| 30 | 0.936 | 0.984 | 0.854 | 0.999 | - - -### Spectral Signatures - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.928 | 0.963 | - | - | -| 0.1 | 0.929 | 0.975 | 0.888 | 0.499 | -| 0.5 | 0.924 | 0.975 | 0.901 | 0.291 | -| 01 | 0.904 | 0.962 | 0.877 | 0.354 | -| 05 | 0.940 | 0.983 | 0.939 | 0.011 | -| 10 | 0.921 | 0.967 | 0.872 | 0.597 | -| 20 | 0.936 | 0.981 | 0.908 | 0.339 | -| 30 | 0.929 | 0.952 | 0.906 | 0.313 | - - - -## Dog Clicker Trigger - -### Undefended - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.939 | 0.985 | - | - | -| 0.1 | 0.923 | 0.989 | 0.887 | 0.440 | -| 0.5 | 0.930 | 0.983 | 0.856 | 0.905 | -| 01 | 0.941 | 0.985 | 0.862 | 0.955 | -| 05 | 0.940 | 0.989 | 0.859 | 0.983 | -| 10 | 0.950 | 0.981 | 0.869 | 0.995 | - - -### Random Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.932 | 0.973 | - | - | -| 0.1 | 0.931 | 0.980 | 0.900 | 0.382 | -| 0.5 | 0.931 | 0.980 | 0.858 | 0.885 | -| 01 | 0.909 | 0.972 | 0.833 | 0.933 | -| 05 | 0.930 | 0.984 | 0.850 | 0.979 | -| 10 | 0.941 | 0.974 | 0.876 | 0.812 | - - -### Perfect Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.918 | 0.993 | - | - | -| 0.1 | 0.931 | 0.979 | 0.931 | 0.001 | -| 0.5 | 0.946 | 0.976 | 0.946 | 0.006 | -| 01 | 0.934 | 0.983 | 0.934 | 0.001 | -| 05 | 0.944 | 0.979 | 0.944 | 0.002 | -| 10 | 0.936 | 0.980 | 0.936 | 0.005 | - - -### Activation Clustering - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.942 | 0.975 | - | - | -| 0.1 | 0.893 | 0.989 | 0.858 | 0.415 | -| 0.5 | 0.929 | 0.985 | 0.857 | 0.884 | -| 01 | 0.939 | 0.982 | 0.863 | 0.928 | -| 05 | 0.931 | 0.979 | 0.850 | 0.984 | -| 10 | 0.936 | 0.960 | 0.857 | 0.994 | - - -### Spectral Signatures - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.923 | 0.980 | - | - | -| 0.1 | 0.926 | 0.983 | 0.921 | 0.059 | -| 0.5 | 0.906 | 0.984 | 0.870 | 0.433 | -| 01 | 0.934 | 0.976 | 0.884 | 0.623 | -| 05 | 0.901 | 0.980 | 0.901 | 0.004 | -| 10 | 0.927 | 0.976 | 0.897 | 0.372 | - - - -## Car Horn Trigger - -### Undefended - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.910 | 0.916 | - | - | -| 001 | 0.932 | 0.988 | 0.870 | 0.749 | -| 005 | 0.937 | 0.987 | 0.859 | 0.947 | -| 01 | 0.935 | 0.984 | 0.857 | 0.953 | -| 05 | 0.940 | 0.985 | 0.860 | 0.975 | -| 10 | 0.933 | 0.989 | 0.851 | 0.985 | - - -### Random Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.922 | 0.984 | - | - | -| 001 | 0.928 | 0.981 | 0.878 | 0.618 | -| 005 | 0.922 | 0.960 | 0.847 | 0.932 | -| 01 | 0.945 | 0.973 | 0.867 | 0.958 | -| 05 | 0.929 | 0.987 | 0.849 | 0.967 | -| 10 | 0.933 | 0.984 | 0.854 | 0.973 | - - -### Perfect Filter - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.948 | 0.987 | - | - | -| 001 | 0.940 | 0.985 | 0.939 | 0.008 | -| 005 | 0.940 | 0.971 | 0.940 | 0.001 | -| 01 | 0.936 | 0.981 | 0.936 | 0.005 | -| 05 | 0.913 | 0.986 | 0.913 | 0.001 | -| 10 | 0.940 | 0.970 | 0.940 | 0.003 | - - -### Activation Clustering - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.929 | 0.984 | - | - | -| 001 | 0.928 | 0.986 | 0.865 | 0.765 | -| 005 | 0.921 | 0.984 | 0.846 | 0.914 | -| 01 | 0.942 | 0.984 | 0.865 | 0.948 | -| 05 | 0.925 | 0.970 | 0.846 | 0.988 | -| 10 | 0.932 | 0.982 | 0.851 | 0.985 | - - -### Spectral Signatures - -| Poison Percentage | Benign all classes | Benign source class | Adv. all classes | Attack success rate | -| ------- | ------- | ------- | ------- | ------- | -| 00 | 0.935 | 0.988 | - | - | -| 001 | 0.930 | 0.971 | 0.903 | 0.322 | -| 005 | 0.928 | 0.981 | 0.913 | 0.181 | -| 01 | 0.928 | 0.980 | 0.917 | 0.141 | -| 05 | 0.933 | 0.983 | 0.893 | 0.484 | -| 10 | 0.935 | 0.976 | 0.933 | 0.026 | diff --git a/docs/original/baseline_results/ucf101_results.md b/docs/original/baseline_results/ucf101_results.md deleted file mode 100644 index 0b8934eca..000000000 --- a/docs/original/baseline_results/ucf101_results.md +++ /dev/null @@ -1,23 +0,0 @@ -# UCF101 Video Classification Baseline Evaluation - -Results obtained using Armory v0.13.3. - -| Attack | Budget | Benign Top1/Top5 Accuracy (Undefended) | Adversarial Top1/Top5 Accuracy (Undefended) | Benign Top1/Top5 Accuracy (Defended) | Adversarial Top1/Top5 Accuracy (Defended) | Test Size | -|:-----------------------------------:|:--------------------------------:|:--------------------------------------:|:-------------------------------------------:|:------------------------------------:|:-----------------------------------------:|:---------:| -| Flicker (low perceptibility) | beta_0=4.0 beta_1=0.1 beta_2=0.9 | 0.92/1.00 | 0.51/1.00 | 0.92/1.00 | 0.44/1.00 | 100 | -| Flicker (medium perceptibility) | beta_0=2.0 beta_1=0.1 beta_2=0.9 | 0.92/1.00 | 0.39/1.00 | 0.92/1.00 | 0.40/0.97 | 100 | -| Flicker (high perceptibility) | beta_0=1.0 beta_1=0.1 beta_2=0.9 | 0.92/1.00 | 0.37/1.00 | 0.92/1.00 | 0.38/0.98 | 100 | -| Frame Border | patch ratio=0.10 | 0.92/1.00 | 0.00/0.25 | 0.93/1.00 | 0.03/0.36 | 100 | -| Frame Border | patch ratio=0.15 | 0.92/1.00 | 0.00/0.19 | 0.93/1.00 | 0.01/0.29 | 100 | -| Frame Border | patch ratio=0.20 | 0.92/1.00 | 0.00/0.19 | 0.93/1.00 | 0.00/0.25 | 100 | -| Masked PGD | patch ratio=0.10 | 0.92/1.00 | 0.02/0.61 | 0.93/1.00 | 0.01/0.66 | 100 | -| Masked PGD | patch ratio=0.15 | 0.92/1.00 | 0.00/0.42 | 0.93/1.00 | 0.00/0.36 | 100 | -| Masked PGD | patch_ratio=0.20 | 0.92/1.00 | 0.00/0.28 | 0.93/1.00 | 0.00/0.31 | 100 | -| Frame Saliency (iterative_saliency) | eps=0.004 | 0.92/1.00 | 0.00/0.96 | 0.92/1.00 | 0.81/1.00 | 100 | -| Frame Saliency (iterative_saliency) | eps=0.008 | 0.92/1.00 | 0.00/0.96 | 0.92/1.00 | 0.47/1.00 | 100 | -| Frame Saliency (iterative_saliency) | eps=0.015 | 0.92/1.00 | 0.00/0.96 | 0.92/1.00 | 0.23/0.99 | 100 | -| Frame Saliency (one_shot) | eps=0.004 | 0.92/1.00 | 0.00/0.26 | 0.93/1.00 | 0.79/0.97 | 100 | -| Frame Saliency (one_shot) | eps=0.008 | 0.92/1.00 | 0.00/0.22 | 0.93/1.00 | 0.46/0.89 | 100 | -| Frame Saliency (one_shot) | eps=0.015 | 0.92/1.00 | 0.00/0.20 | 0.93/1.00 | 0.21/0.74 | 100 | - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/scenario_configs) diff --git a/docs/original/baseline_results/xview_results.md b/docs/original/baseline_results/xview_results.md deleted file mode 100644 index 4cc221b30..000000000 --- a/docs/original/baseline_results/xview_results.md +++ /dev/null @@ -1,14 +0,0 @@ -# xView Object Detection Baseline Evaluation (Updated July 2021) - -results obtained using Armory v0.13.3 - -| Attack | Patch Size | Benign mAP (Undefended) | Adversarial mAP (Undefended) | Benign mAP (Defended) | Adversarial mAP (Defended) | Test Size | -|:-------------:|:----------:|:-----------------------:|:----------------------------:|:---------------------:|:--------------------------:|:---------:| -| Masked PGD | 50x50 | 0.284 | 0.142 | 0.232 | 0.139 | 100 | -| Masked PGD | 75x75 | 0.284 | 0.071 | 0.232 | 0.094 | 100 | -| Masked PGD | 100x100 | 0.284 | 0.076 | 0.232 | 0.092 | 100 | -| Robust DPatch | 50x50 | 0.284 | 0.193 | 0.232 | 0.184 | 100 | -| Robust DPatch | 75x75 | 0.284 | 0.184 | 0.232 | 0.146 | 100 | -| Robust DPatch | 100x100 | 0.284 | 0.173 | 0.232 | 0.165 | 100 | - -Find reference baseline configurations [here](https://github.com/twosixlabs/armory/tree/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/scenario_configs) diff --git a/docs/original/command_line.md b/docs/original/command_line.md deleted file mode 100644 index a8650ef3f..000000000 --- a/docs/original/command_line.md +++ /dev/null @@ -1,131 +0,0 @@ -# Command Line Usage - -## Root -* `armory --root [...]` -Applies to `run`, `launch`, and `exec` commands. - -This will run the docker container as root instead of the host user. -NOTE: this is incompatible with `--no-docker` mode. -NOTE: `--jupyter` only runs as root currently, and will ignore this argument. - -### Example Usage - -To run a single scenario as root: -``` -armory run official_scenario_configs/cifar10_baseline.json --root -``` - -To accept a config file from standard in: -``` -more official_scenario_configs/cifar10_baseline.json | armory run - -``` - -To execute the `id` command in the container: -``` -$ python -m armory exec pytorch --root -- id -2020-07-15 15:02:20 aleph-5.local armory.docker.management[35987] INFO ARMORY Instance c1045b0ed3 created. -2020-07-15 15:02:20 aleph-5.local armory.eval.evaluator[35987] INFO Running bash command: id -uid=0(root) gid=0(root) groups=0(root) -... -``` - -## GPUs -* `armory --gpus=X [...]` -* `armory --use-gpu [...]` -Applies to `run`, `launch`, and `exec` commands. - -This will specify whether to run GPUs and which ones to run. -If the `--gpus` flag is used, it will set `--use-gpu` to True. -The argument `X` for `--gpus` can be a single number, "all", -or a comma-separated list of numbers without spaces for multiple GPUs. - -The `--use-gpu` flag will simply enable gpus. -If a config is being run, the gpus used will be pulled from the config. -If a config is not being run or that field is not in the config, it will default to all. - -NOTE: when running a config, these will overwrite the fields inside the config. - -### Example Usage - -Examples: -``` -armory run scenario_configs/mnist_baseline.json --use-gpu -armory launch tf2 --gpus=1,4 --interactive -armory exec pytorch --gpus=0 -- nvidia-smi -``` - -## Check Runs, Number of Example Batches, Indexing, and Class Filtering -* `armory run --check [...]` -* `armory run --num-eval-batches=X [...]` -* `armory run --index=a,b,c [...]` -* `armory run --classes=x,y,z [...]` -Applies to `run` command. - -The `--check` flag will make every dataset return a single batch, -which is useful to quickly check whether the entire scenario correctly runs. -It will also ensure that the number of training epochs and certain attack parameters are set to 1. - -The `--num-eval-batches` argument will truncate the number of batches used in -both benign and adversarial test sets. -It is primarily designed for attack development iteration, where it is typically unhelpful -to run more than 10-100 examples. - -The `--index` argument will only use samples from the comma-separated, non-negative list of numbers provided. -Any duplicate numbers will be removed and the list will be sorted. -If indices beyond the size of the dataset are provided, an error will result at runtime. -Cannot be used with the `--num-eval-batches` argument. -Currently, batch size must be set to 1. - -The `--classes` argument will only use samples from the comma-separated, non-negative list of numbers provided. -Any duplicate numbers will be removed and the list will be sorted. -If indices beyond the size of the dataset are provided, an error will result at runtime. -Can be used with `--index` argument. In that case, indexing will be done after class filtering. - -NOTE: `--check` will take precedence over the `--num-eval-batches` argument. - -### Example Usage - -``` -armory run scenario_configs/mnist_baseline.json --check -armory run scenario_configs/mnist_baseline.json --num-eval-batches=5 -``` - -## Model Validation -The `--validate-config` flag will run a series of tests on the model in the selected configuration file. These tests will alert the user to configuration errors (e.g. clip values that do not broadcast correctly to the input), as well as circumstances that may limit the evaluation (e.g. a model without gradients won't work with white box attacks without modification). - -### Example Usage -``` -armory run scenario_configs/so2sat_baseline.json --validate-config -``` - -## Skipping Benign Evaluation / Attack Generation -The `--skip-benign` and `--skip-attack` flags allow the user to skip, respectively, evaluating on benign samples and generating/evaluating attack samples. - -### Example Usage -``` -armory run scenario_configs/mnist_baseline.json --skip-benign -armory run scenario_configs/mnist_baseline.json --skip-attack -``` - -## Skipping Attack of Misclassified Samples -When `--skip-misclassified` is enabled, for benign examples that yield a misclassification, Armory will simply reuse the -benign sample rather than running an attack. Note: the following criteria must be met when `--skip-misclassified` is enabled: - -1. The scenario must be a classification task (i.e. *not* object detection, ASR) with the 'categorical_accuracy' metric enabled in the config file. -2. Batch size must be set to 1 -3. The `--skip-benign` and `--skip-attack` flags cannot also be enabled - -### Example Usage -``` -armory run scenario_configs/mnist_baseline.json --skip-misclassified -``` - -## command line arguments and sysconfig - -For convenience, command line control arguments can be specified in the "sysconfig" -block of an evaluation configuration. Adding control to the configuration is -described in [Configuration Files][conf]. Command line arguments will override -sysconfig specifications. - - - [conf]: configuration_files.md#sysconfig-and-command-line-arguments diff --git a/docs/original/configuration_files.md b/docs/original/configuration_files.md deleted file mode 100644 index 48940b595..000000000 --- a/docs/original/configuration_files.md +++ /dev/null @@ -1,235 +0,0 @@ -# Configuration Files - -All configuration files are verified against the jsonschema definition at run time: -[armory/utils/config_schema.json](https://github.com/twosixlabs/armory/blob/master/armory/utils/config_schema.json) - -## Schema -``` -`_description`: [String] Any description that describes the scenario evaluation -`adhoc`: [Object or null] - { - Custom parameters that you can access within a scenario - } -`attack`: [Object or null] - { - knowledge: [String] `white` or `black` knowledge - kwargs: [Object] Keyword arguments to pass to attack instatiation - module: [String] Python module to load attack from - name: [String] Name of the attack class to be instatiated - use_label: [Bool] Default: False. Whether attack should use the true label when - attacking the model. Without this, it is not possible to drive the accuracy - down to 0% when the model has misclassifications. - type: [Optional String]: in <`preloaded`|`patch`|`sweep`>. - } -`dataset`: [Object] - { - batch_size [Int]: Number of samples to include in each batch - module: [String] Python module to load dataset from - name: [String] Name of the dataset function - framework: [String] Framework to return Tensors in. <`tf`|`pytorch`|`numpy`>. `numpy` by default. - train_split: [Optional String] Training split in dataset. Typically defaults to `train`. Can use fancy slicing via [TFDS slicing API](https://www.tensorflow.org/datasets/splits#slicing_api) - eval_split: [Optional String] Eval split in dataset. Typically defaults to `test`. Can use fancy slicing via [TFDS slicing API](https://www.tensorflow.org/datasets/splits#slicing_api) - class_ids: [Optional Int or List[Int]] Class ID's to filter the dataset to. Can use a numeric list like [1, 5, 7] or a single integer. - index: [Optional String or Object] Index into the post-sorted (and post-filtered if class_ids is enabled) eval dataset. Can use a numeric list like [1, 5, 7] or a simple slice as a string, like "[3:6]" or ":100". - } -`defense`: [Object or null] - { - kwargs: [Object] Keyword arguments to pass to defense instatiation - module: [String] Python module to load defense from - name: [String] Name of the defense class to be utilized - type: [String] Type of defense which flags how it should be used. One of - } -`metric`: [Object or null] - { - means: [Bool] Boolean to caculate means for each task in logging / output - perturbation: [String] Perturbation metric to calculate for adversarial examples - record_metric_per_sample: [Bool] Boolean to record metric for every sample in save in output - task: [List[String]] List of task metrics to record (e.g. categorical_accuracy) - profiler_type: [Optional String or null] Type of computational resource profiling desired for scenario profiling. One of or null - } -`model`: [Object] - { - fit: [Bool] Boolean to train the model or not - fit_kwargs: [Object] Keyword arguments to pass to `fit_generator` or `fit` - module: [String] Python module to load model from - name: [String] Name of the function to return ART classifier - model_kwargs: [Object] Keyword arguments to load model function - weights_file: [String or null] Name of pretrained weights file. Will be downloaded from S3 if available - wrapper_kwargs: [Object] Keyword arguments to ART wrapper function - } -`scenario`: [Object] - { - kwargs: [Object] Keyword arguments to pass to Scenario instatiation - module: [String] Python module to load scenario from - name: [String] Name of the scenario class to be ran - export_batches: [Optional Int or Bool] Number of batches of data to export - } -`sysconfig` [Object] - { - docker_image: [String or null] Docker image name and tag to run scenario in - external_github_repo: [String or null or Object] External github repository(s) to download and place on PYTHONPATH within container - external_github_repo_pythonpath: [String or null or Object] Relative path(s) in the repo directory to add to PYTHONPATH within container - gpus: [String]: Which GPUs should the docker container have access to. "all" or comma sperated list (e.g. "1,3") - local_repo_path: [String or null or Object] Local github repository path(s) to place on PYTHONPATH within container - output_dir: [Optional String]: Add an optional output directory prefix to the default output directory name. - output_filename: [Optional String]: Optionally change the output filename prefix (from default of scenario name) - use_gpu: [Boolean]: Boolean to run container as nvidia-docker with GPU access - } -`user_init`: [Object or null] - { - module: [String] Python module to import before scenario loading but after scenario initialization - name: [String or null] Name of the function to call after module import (optional) - kwargs: [Object or null] Keyword arguments to provide for function call (optional) - } -``` - - -### Example Configuration File: -``` -{ - "_description": "Baseline cifar10 image classification", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.031, - "eps_step": 0.007, - "max_iter": 20, - "num_random_init": 1, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "use_label": true - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.cifar", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} -``` - -### attack config "type" field -The supported values for the `"type"` field in attack configs are as follows: -<`preloaded`|`patch`|`sweep`>. If none of the cases below apply, the field -does not need to be included. - -1. `"preloaded"`: This value is specified when using an adversarial dataset (e.g. APRICOT) where no -perturbations should be applied to the inputs. - -2. `"patch"`: Some ART attacks such as `"AdversarialPatch"` or `"RobustDPatch"` have a `generate()` method -which returns a patch rather than the input with patch. When using such an attack in an Armory scenario, -setting `attack_config["type"]` to `"patch"` will enable an Armory wrapper class with an updated -`generate()` which applies the patch to the input. - -2. `"sweep"`: To enable "sweep" attacks, see the instructions in [sweep_attacks.md](sweep_attacks.md). - -### Use with Custom Docker Image - -To run with a custom Docker image, replace the `["sys_config"]["docker_image"]` field -to your custom docker image name ``. - -### Specifying kwargs for metric functions -Some metric functions in [armory/utils/metrics.py](../armory/utils/metrics.py) receive kwargs, e.g. -`iou_threshold` in the case of `object_detection_AP_per_class()`. To modify the kwarg, specify -`"task_kwargs"` in the `"metric"` portion of the config file as such: - -```json -"metric": { - "task": [ - "object_detection_AP_per_class", - "object_detection_true_positive_rate" - ], - "task_kwargs": [{"iou_threshold": 0.3}, {}] -} -``` -Note that the length of `"task_kwargs"` should be equal to that of `"task"`, as `task_kwargs[i]` corresponds -to `task[i]`. - -### Exporting Data -Please see [exporting_data.md](exporting_data.md). - -### Additional configuration settings for poisoning scenario - -Some settings specific to the poisoning scenario are not applicable to the other -scenarios and are thus found in "adhoc" subfield of the configuration file. - -For a poison filtering defense, Armory supports using a model for filtering that -differs from the model used at training time. The model used at training time should -still be stored in the field "model" as described in the config schema. However, if a -different model is used for the filtering defense, it should be entered in the "ad-hoc" -field of the configuration file under the subfield "defense_model," with the number of -epochs of training under the subfield "defense_model_train_epochs." A concrete example -of a configuration with this field is available in the armory-example -[repo](https://github.com/twosixlabs/armory-example/tree/master/example_scenario_configs). - -### sysconfig and command line arguments - -Parameters specified in the "sysconfig" block will be treated as if they were passed -as arguments to `armory` for example a configuration block like -```json -{ - "sysconfig": { - "num_eval_batches": 5, - "skip_benign": true - } -} -``` -will cause armory to act as if you had run it as -``` -armory run scenario.json --num-eval-batches 5 --skip-benign -``` -However, arguments actually specified on the command line will take precedence, -so if you execute, using the same configuration file -``` -armory run scenario.json --num-eval-batches 100 -``` -Then the command line will override the sysconfig and 100 batches (not 5) will -be run. In this example, `--skip-benign` will also be true because it is -in the sysconfig block. - -No matter whether these attributes are specified on the command line, in sysconfig, -or both, the output file will record the attributes as executed, so you have a -record of how the evaluation ultimately ran. - -The [full specification of command line arguments][cmdline] is available. - - [cmdline]: command_line.md diff --git a/docs/original/contributing/self-review.md b/docs/original/contributing/self-review.md deleted file mode 100644 index 8bbff6de3..000000000 --- a/docs/original/contributing/self-review.md +++ /dev/null @@ -1,11 +0,0 @@ -### Self review - -You should always review your own PR first. - -For content changes, make sure that you: - -- [ ] Confirm that the changes meet the user experience and goals outlined in the content design plan (if there is one). -- [ ] Compare your pull request's source changes to staging to confirm that the output matches the source and that everything is rendering as expected. This helps spot issues like typos, content that doesn't follow the style guide, or content that isn't rendering due to versioning problems. Remember that lists and tables can be tricky. -- [ ] Review the content for technical accuracy. -- [ ] Copy-edit the changes for grammar, spelling, and adherence to the [style guide](/docs/style.md). -- [ ] If there are any failing checks in your PR, troubleshoot them until they're all passing. diff --git a/docs/original/dataset_licensing.md b/docs/original/dataset_licensing.md deleted file mode 100644 index 904f3f183..000000000 --- a/docs/original/dataset_licensing.md +++ /dev/null @@ -1,158 +0,0 @@ -## Dataset Licensing - -Armory datasets are either licensed or available in accordance to the fair use -exception to copyright infringement. The passthrough license is the same as the original -license for nonadapted datasets. Adapted datasets ("derivative works") are licensed under -the Creative Commons 4.0 International ShareAlike license and are Copyright Two Six Labs, 2020. - -## Original Licenses - -| Dataset | Original license | -|:-:|:-:| -| MNIST | [Creative Commons Attribution-Share Alike 3.0](http://www.pymvpa.org/datadb/mnist.html) | -| CIFAR-10 | [MIT](https://peltarion.com/knowledge-center/documentation/terms/dataset-licenses/cifar-10)| -| Digit | [Creative Commons Attribution-ShareAlike 4.0 International](https://github.com/Jakobovski/free-spoken-digit-dataset) | -| Librispeech | [Creative Commons 4.0](http://www.openslr.org/12/) | -| GTSRB | [CC0 Public Domain](https://www.kaggle.com/meowmeowmeowmeowmeow/gtsrb-german-traffic-sign)| -| Imagenette | [Apache 2.0](https://github.com/fastai/imagenette/blob/master/LICENSE) | -| UCF101 | Fair use exception | -| RESISC45 | Fair use exception | (http://xviewdataset.org/) -| xView | [Creative Commons Attribution-Noncommercial-ShareAlike 4.0 International](https://arxiv.org/pdf/1802.07856) | -| so2sat | [Creative Commons 4.0](https://mediatum.ub.tum.de/1454690) | -| APRICOT | [Apache License Version 2.0](https://apricot.mitre.org/) | -| DAPRICOT | Creative Commons 4.0 | -| CARLA | MIT | -| Speech Commands | [Creative Commons BY 4.0](https://ai.googleblog.com/2017/08/launching-speech-commands-dataset.html) - -## Attributions - -Note: attribution material can be removed upon request to the extent reasonably -practicable. Please direct inquiries to . - -### MNIST -|Attribution | | -|------------------------------|--------------| -| Creator/author name | Yann LeCun and Corinna Cortes | -| Copyright notice | Copyright © 1998 by Yann LeCun and Corinna Cortes | -| Public license notice | http://www.pymvpa.org/datadb/mnist.html | -| Disclaimer notice | UNLESS OTHERWISE MUTUALLY AGREED TO BY THE PARTIES IN WRITING, LICENSOR OFFERS THE WORK AS-IS AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE WORK, EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTIBILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT, OR THE ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OF ABSENCE OF ERRORS, WHETHER OR NOT DISCOVERABLE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO SUCH EXCLUSION MAY NOT APPLY TO YOU. | -| Dataset link | http://yann.lecun.com/exdb/mnist/ | -| Modification | (Slight) Representation of images as binary tensors | -| Citation | LeCun, Yann, Corinna Cortes, and Christopher JC Burges. "The MNIST database of handwritten digits, 1998." URL http://yann.lecun.com/exdb/mnist 10, no. 34 (1998): 14. | - -### CIFAR-10 -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Alex Krizhevsky, Vinod Nair, and Geoffrey Hinton | -| Copyright notice | Copyright © 2013 by Valay Shah | -| Public license notice | https://peltarion.com/knowledge-center/documentation/terms/dataset-licenses/cifar-10 | -| License text (including disclaimer)| Copyright (c) 2013 Valay Shah. Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The foregoing copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.| -| Dataset link | https://www.cs.toronto.edu/~kriz/cifar.html | -| Citation | Krizhevsky, Alex. "Learning Multiple Layers of Features from Tiny Images." URL https://www.cs.toronto.edu/~kriz/learning-features-2009-TR.pdf, (2009). | -| Modification | (Slight) Representation of images as binary tensors | - -### Free Spoken Digit Dataset (FSDD) -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Zohar Jackson, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite| -| Copyright notice | Copyright © 2018 by Zohar Jackson, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite | -| Public license notice | https://github.com/Jakobovski/free-spoken-digit-dataset | -| Disclaimer notice | a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | https://github.com/Jakobovski/free-spoken-digit-dataset | -| Citation | Jackson, Zohar, César Souza, Jason Flaks, Yuxin Pan, Hereman Nicolas, and Adhish Thite. "Jakobovski/free-spoken-digit-dataset: v1.0.8 (Version v1.0.8)." Zenodo (2018). URL http://doi.org/10.5281/zenodo.134240 | -| Modification | (Slight) Representation of audio wav file as one-dimensional binary tensors | - -### Librispeech -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Vassil Panayotov, Guoguo Chen, Daniel Povey and Sanjeev Khudanpur | -| Copyright notice | Copyright © 2014 by Vassil Panayotov | -| Public license notice | http://www.openslr.org/12/ | -| Disclaimer notice | a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | http://www.openslr.org/12/ | -| Citation | Panayotov, Vassil, Guoguo Chen, Daniel Povey, and Sanjeev Khudanpur. "Librispeech: an ASR corpus based on public domain audio books." In 2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 5206-5210. IEEE, 2015. | -| Modification | (Derivative work) Creation of adversarial dataset that modifies the original audio with small perturbations that are crafted to fool machine learning models. | - -### GTSRB -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel | -| Copyright notice | N/A (public domain) | -| Public license notice | https://www.kaggle.com/meowmeowmeowmeowmeow/gtsrb-german-traffic-sign | -| Disclaimer notice | Affirmer offers the Work as-is and makes no representations or warranties of any kind concerning the Work, express, implied, statutory or otherwise, including without limitation warranties of title, merchantability, fitness for a particular purpose, non infringement, or the absence of latent or other defects, accuracy, or the present or absence of errors, whether or not discoverable, all to the greatest extent permissible under applicable law. Affirmer disclaims responsibility for clearing rights of other persons that may apply to the Work or any use thereof, including without limitation any person's Copyright and Related Rights in the Work. Further, Affirmer disclaims responsibility for obtaining any necessary consents, permissions or other rights required for any use of the Work. | -| Dataset link | http://benchmark.ini.rub.de/?section=gtsrb&subsection=dataset | -| Citation | Stallkamp, Johannes, Marc Schlipsing, Jan Salmen, and Christian Igel. "Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition." Neural Networks, URL http://www.sciencedirect.com/science/article/pii/S0893608012000457, (2012)| -| Modification | (Derivative work) Creation of adversarial dataset that modifies the original images with small perturbations that are crafted to fool machine learning models. | - -### Imagenette -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Jeremy Howard | -| Copyright notice | Copyright © 2019 by Jeremy Howard | -| Public license notice | https://github.com/fastai/imagenette | -| Disclaimer notice | Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License. | -| Dataset link | https://github.com/fastai/imagenette | -| Modification | (Slight) Representation of images as binary tensors | - -### xView -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Defense Innovation Unit Experimental (DIUx) and the National Geospatial-Intelligence Agency (NGA) | -| Copyright notice | None found | -| Public license notice | http://xviewdataset.org/terms.html | -| Disclaimer notice | Disclaimer of Warranties and Limitation of Liability. a. Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You. b. To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | http://xviewdataset.org/#dataset | -| Modification | (Slight) Representation of images as binary tensors | - -### so2sat -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | Xiaoxiang Zhu, Jingliang Hu, Chunping Qiu, Yilei Shi, Jian Kang, Lichao Mou, Hossein Bagheri, Matthias Haeberle, Yuansheng Hua, Rong Huang, Lloyd Hughes, Hao Li, Yao Sun, Guichen Zhang, Shiyao Han, Michael Schmitt, and Yuanyuan Wang | -| Copyright notice | None found | -| Public license notice | https://mediatum.ub.tum.de/1454690 | -| Disclaimer notice | a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU. b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION, NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES, COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR IN PART, THIS LIMITATION MAY NOT APPLY TO YOU. c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. | -| Dataset link | https://mediatum.ub.tum.de/1454690 | -| Modification | (Slight) Representation of images as binary tensors | - -### APRICOT -|Attribution | | -|------------------------------|--------------| -| Creator/attribution parties | A. Braunegg, Amartya Chakraborty, Michael Krumdick, Nicole Lape, Sara Leary, Keith Manville, Elizabeth Merkhofer, Laura Strickhart, and Matthew Walmer | -| Copyright notice | Copyright 2020 APRICOT - MITRE Corporation | -| Public license notice | https://apricot.mitre.org/ | -| Disclaimer notice | Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License. | -| Dataset link | https://apricot.mitre.org/ | -| Modification | (Slight) Representation of images as binary tensors | - -## Fair use notes for RESISC-45 and UCF101 -* Two Six Labs does not charge users for access to the Armory repository, -nor the datasets therein, nor does it derive a profit directly from use of the -datasets. -* Two Six Labs is not merely republishing the original datasets. The -datasets have undergone transformative changes, specifically they have been -repackaged to be integrated with Tensorflow Datasets. This repackaging -includes, but is not limited to, processing images from compressed formats into -binary tensors as well as decoding audio and video files. Further, Two Six Labs -has published derived adversarial datasets that modify the original images/videos with -small perturbations that are crafted to fool machine learning models for both -the RESISC-45 and UCF101 datasets. -* Two Six Labs uses these datasets within Armory, however there are -other additional datasets present, as well as multiple other features present -in Armory beyond providing datasets. -* Two Six Labs attempted to contact the authors of RESISC-45, but received no -response. -* UCF101 direct download functionality has been used by other machine learning -frameworks, such as TensorFlow: https://www.tensorflow.org/datasets/catalog/ucf101 -* Two Six Labs provides public benefit through the public distribution -of the Armory framework to evaluate machine learning models. This material is -based upon work supported by the Defense Advanced Research Projects Agency -(DARPA) under Contract No. HR001120C0114. Any opinions, findings and -conclusions or recommendations expressed in this material are those of the -author(s) and do not necessarily reflect the views of the Defense Advanced -Research Projects Agency (DARPA). - -### Citations for RESISC45 and UCF101 - -Cheng, Gong, Junwei Han, and Xiaoqiang Lu. "Remote sensing image scene classification: Benchmark and state of the art." Proceedings of the IEEE 105, no. 10 (2017): 1865-1883. - -Soomro, Khurram, Amir Roshan Zamir, and Mubarak Shah. "UCF101: A dataset of 101 human actions classes from videos in the wild." arXiv preprint arXiv:1212.0402 (2012). diff --git a/docs/original/datasets.md b/docs/original/datasets.md deleted file mode 100644 index 681147a2a..000000000 --- a/docs/original/datasets.md +++ /dev/null @@ -1,117 +0,0 @@ -# Datasets - -The `armory.data.datasets` module implements functionality to return datasets of -various data modalities. By default, this is a NumPy `ArmoryDataGenerator` which -implements the methods needed by the ART framework. Specifically `get_batch` will -return a tuple of `(data, labels)` for a specified batch size in numpy format. - -We have experimental support for returning `tf.data.Dataset` and -`torch.utils.data.Dataset`. These can be specified with the `framework` argument to -the dataset function. Options are ``. - -Currently, datasets are loaded using TensorFlow Datasets from cached tfrecord files. -These tfrecord files will be pulled from S3 if not available on your -`dataset_dir` directory. - -### Image Datasets - -| Dataset | Description | x_shape | x_dtype | y_shape | y_dtype | splits | -|:----------: |:-----------: |:-------: |:--------: |:--------: |:-------: |:------: | -| [cifar10](https://www.cs.toronto.edu/~kriz/cifar.html) | CIFAR 10 classes image dataset | (N, 32, 32, 3) | float32 | (N,) | int64 | train, test | -| [german_traffic_sign](http://benchmark.ini.rub.de/?section=gtsrb&subsection=dataset) | German traffic sign dataset | (N, variable_height, variable_width, 3) | float32 | (N,) | int64 | train, test | -| [imagenette](https://github.com/fastai/imagenette) | Smaller subset of 10 classes from Imagenet | (N, variable_height, variable_width, 3) | uint8 | (N,) | int64 | train, validation | -| [mnist](http://yann.lecun.com/exdb/mnist/) | MNIST hand written digit image dataset | (N, 28, 28, 1) | float32 | (N,) | int64 | train, test | -| [resisc45](https://arxiv.org/abs/1703.00121) | REmote Sensing Image Scene Classification | (N, 256, 256, 3) | float32 | (N,) | int64 | train, validation, test | -| [Coco2017](https://arxiv.org/abs/1405.0312) | Common Objects in Context | (N, variable_height, variable_width, 3) | float32 | n/a | List[dict] | train, validation, test | -| [xView](https://arxiv.org/pdf/1802.07856) | Objects in Context in Overhead Imagery | (N, variable_height, variable_width, 3) | float32 | n/a | List[dict] | train, test | - -NOTE: the Coco2017 dataset's class labels are 0-indexed (start from 0). -
- -### Multimodal Image Datasets -| Dataset | Description | x_shape | x_dtype | y_shape | y_dtype | splits | -|:----------: |:-----------: |:----------------------:|:--------: |:--------: |:-------: |:-----------------:| -| [so2sat](https://mediatum.ub.tum.de/1454690) | Co-registered synthetic aperture radar and multispectral optical images | (N, 32, 32, 14) | float32 | (N,) | int64 | train, validation | -| [carla_obj_det_train](https://carla.org/) | CARLA Simulator Object Detection | (N, 960, 1280, 3 or 6) | float32 | n/a | List[dict] | train, val | -| [carla_over_obj_det_train](https://carla.org/) | CARLA Simulator Object Detection | (N, 960, 1280, 3 or 6) | float32 | n/a | List[dict] | train, val | -
- -##### CARLA Object Detection -The carla_obj_det_train dataset contains rgb and depth modalities. The modality defaults to rgb and must be one of `["rgb", "depth", "both"]`. -When using the dataset function imported from [armory.data.datasets](../armory/data/datasets.py), this value is passed via the `modality` kwarg. When running an Armory scenario, the value -is specified in the dataset_config as such: -```json - "dataset": { - "batch_size": 1, - "modality": "rgb", -} -``` -When `modality` is set to `"both"`, the input will be of shape `(nb=1, 960, 1280, 6)` where `x[..., :3]` are -the rgb channels and `x[..., 3:]` the depth channels. - -The carla_over_obj_det_train dataset has the same properties as the above mentioned dataset but is collected utilizing overhead perspectives. - - -### Audio Datasets -| Dataset | Description | x_shape | x_dtype | y_shape | y_dtype | sampling_rate | splits | -|:----------: |:-----------: |:-------: |:--------: |:--------: |:-------: |:-------: |:------: | -| [digit](https://github.com/Jakobovski/free-spoken-digit-dataset) | Audio dataset of spoken digits | (N, variable_length) | int64 | (N,) | int64 | 8 kHz | train, test | -| [librispeech](http://www.openslr.org/12/) | Librispeech dataset for automatic speech recognition | (N, variable_length) | float32 | (N,) | bytes | 16 kHz | dev_clean, dev_other, test_clean, train_clean100 | -| [librispeech-full](http://www.openslr.org/12/) | Full Librispeech dataset for automatic speech recognition | (N, variable_length) | float32 | (N,) | bytes | 16 kHz | dev_clean, dev_other, test_clean, train_clean100, train_clean360, train_other500 | -| [librispeech_dev_clean](http://www.openslr.org/12/) | Librispeech dev dataset for speaker identification | (N, variable_length) | float32 | (N,) | int64 | 16 kHz | train, validation, test | -| [librispeech_dev_clean_asr](http://www.openslr.org/12) | Librispeech dev dataset for automatic speech recognition | (N, variable_length) | float32 | (N,) | bytes | 16 kHz | train, validation, test | -| [speech_commands](https://www.tensorflow.org/datasets/catalog/speech_commands) | Speech commands dataset for audio poisoning | (N, variable_length) | float32 | (N,) | int64 | 16 kHz | train, validation, test | - -NOTE: because the Librispeech dataset is over 300 GB with all splits, the ```librispeech_full``` dataset has -all splits, whereas the ```librispeech``` dataset does not have the train_clean360 or train_other500 splits. -
- -### Video Datasets -| Dataset | Description | x_shape | x_dtype | y_shape | y_dtype | splits | -|:----------: |:-----------: |:-------: |:--------: |:--------: |:-------: |:------: | -| [ucf101](https://www.crcv.ucf.edu/data/UCF101.php) | UCF 101 Action Recognition | (N, variable_frames, None, None, 3) | float32 | (N,) | int64 | train, test | -| [ucf101_clean](https://www.crcv.ucf.edu/data/UCF101.php) | UCF 101 Action Recognition | (N, variable_frames, None, None, 3) | float32 | (N,) | int64 | train, test | - -NOTE: The dimension of UCF101 videos is `(N, variable_frames, 240, 320, 3)` for the entire training set and all of the test set except for 4 examples. -For those, the dimensions are `(N, variable_frames, 226, 400, 3)`. If not shuffled, these correspond to (0-indexed) examples 333, 694, 1343, and 3218. -NOTE: The only difference between `ucf101` and `ucf101_clean` is that the latter uses the ffmpeg flag `-q:v 2`, which results in fewer video compression errors.These are stored as separate datasets, however. - -
- - -### Preprocessing - -Armory applies preprocessing to convert each dataset to canonical form (e.g. normalize the range of values, set the data type). -The poisoning scenario loads its own custom preprocessing, however the GTSRB data is also available in its canonical form. -Any additional preprocessing that is desired should occur as part of the model under evaluation. - -Canonical preprocessing is not yet supported when `framework` is `tf` or `pytorch`. - -### Splits - -Datasets that are imported directly from TFDS have splits that are defined according to the -Tensorflow Datasets [library](https://www.tensorflow.org/datasets/catalog/overview). The -`german-traffic-sign` dataset split follows the description of the original source of the -[dataset](http://benchmark.ini.rub.de/?section=gtsrb&subsection=dataset). The `digits` - dataset split follows the description of the original source of the - [dataset](https://github.com/Jakobovski/free-spoken-digit-dataset#usage). The following - table describes datasets with custom splits in Armory. -| Dataset | Split | Description | Split logic details | -|:---------------------:|:----------:|:--------------------------------------:|:------------------------------------------------------:| -| resisc_45 | train | First 5/7 of dataset | See armory/data/resisc45/resisc45_dataset_partition.py | -| | validation | Next 1/7 of dataset | | -| | test | Final 1/7 of dataset | | -| librispeech_dev_clean | train | 1371 recordings from dev_clean dataset | Assign discrete clips so at least 50% of audio time | -| | validation | 692 recordings from dev_clean dataset | is in train, at least 25% is in validation, | -| | test | 640 recordings from dev_clean dataset | and the remainder are in test | - - -
- - -### Adversarial Datasets -See [adversarial_datasets.md](adversarial_datasets.md) for descriptions of Armory's adversarial datasets. - -### Dataset Licensing -See [dataset_licensing.md](dataset_licensing.md) for details related to the licensing of datasets. - diff --git a/docs/original/developers/callchain.md b/docs/original/developers/callchain.md deleted file mode 100644 index 2503ca657..000000000 --- a/docs/original/developers/callchain.md +++ /dev/null @@ -1,26 +0,0 @@ -# bootstrap process creation and command line arguments - -This traces how command options percolate through armory instantiation - -`armory.__main__.py` is the entry point for armory run. It has an `if __name__` block on -line 322 which calls main(). main() looks at only the first argument given (e.g. armory -**run**) and uses `run` as a lookup into a dispatch table COMMANDS which maps "run" -> -function `run`. run at line 284 does a bunch of argparse on the residual arguments, -loads the experiment config, constructs an Evaluator and then calls its run method. - -`armory.eval.evaluator.Evaluator __init__` modifies the in-core experiment, sets up a -docker_client and other miscellany. the Evaluator.run method does some more prep and -then calls Evaluator.run_config which conses up a python command line with a base64 -encoded experiment and then calls Evaluator.run_command which calls -armory.docker.management.exec_cmd which runs that encoded command inside a container. - -That encoded command is `python -m armory.scenarios.main` which passes control via python -built-in hidden runpy.py which is currently complaining about import order in a way that -scares me: -> RuntimeWarning: 'armory.scenarios.main' found in sys.modules after import of -package 'armory.scenarios', but prior to execution of 'armory.scenarios.main'; this may -result in unpredictable behavior - -In armory.scenarios.main in the `if __name__` block, first we have an independent -duplicate (and out of sync) argument processor which then calls main.run_config which -calls scenario.evaluate which finally runs application code. diff --git a/docs/original/developers/config-object.md b/docs/original/developers/config-object.md deleted file mode 100644 index e8cf418b4..000000000 --- a/docs/original/developers/config-object.md +++ /dev/null @@ -1,90 +0,0 @@ -# an Armory Configuration object - -As of armory 0.14.x application configuration is built up from various sources -and bits of it are sprinkled through the armory application. This results in -application state distributed hodge-podge through the app. Because the app -configuration is built piece-wise by multiple modules, proper unit test rigging -is difficult or impossible without hoisting the whole system up first. - -This note outlines a configuration object to contain and render all application -configuration state. The state object is unrelated to armory "configurations", -represented by JSON blobs. The old configurations are now to be called "experiments" -because it is more descriptive. - -## the ConfigurationTin class - -There will be one object that contains all configuration data. For lack of -a better name at the moment, I'm calling it a ConfigurationTin. - - @dataclass - class ConfigurationTin: - mode: str - flag: ArmoryFlags - credential: ArmoryCredentials - path: ArmoryPaths - -Typical use is like - - from armory.configuration import tin - - tin = ConfigurationTin(…) - - if tin.mode == 'docker': - docker_mount(tin.path.output_dir) - ... - armory.eval.run(tin, experiment) - -But a test should be able to construct a ConfigurationTin from scratch like - - def test_with_overrides(): - my_tin = ConfigurationTin(overrides of some kind) - armory.eval.run(my_tin, experiment) - -## immutability declined - -Python dataclasses can be marked as `frozen` but I'm not doing that to start. The armory -code currently modifies configuration all throughout which is a bad thing. When -converting to ConfigurationTin, we will know where all mutation happens because we will -have written it. - -By getting the configuration modification well constructed, and having obvious -means of reading it, I expect the developer temptation to alter the tin will be -greatly reduced, and if it sneaks in, it will be much more obvious in review. -As the python maxim goes "we're all adults here" - -## merging ConfigurationTins - -We want the hierarchical override of configuration items drawn from: - - 1. armory defaults - 2. overrides in the experiment file (aka config.json) - 2. overrides from environment variables - 4. override with command line arguments - -As an example num-eval-batches is an experiment parameter that a user wants to -modify. - -This mechanism does (not yet) address the hierarchical construction of configuration -which we think we want. If we used a json-like "bag of properties" as a `Dict[str, Any]` -we could use `dict.update` to trivially implement overrides. This desire does contain -a presupposition that we'd have a dictionary of modifiers to merge in. In actuality, -we'd have to construct that set of modifiers first, so why not use the -dataclass constructors for that? - -There could be a method that handles this example - - args = argparse.parse() - override: ArmoryFlags = tin.flag.copy() - override.flag.skip_attack = args.skip_attack - tin.meld(flag=override) - -But I don't know that buys us anything over: - - tin.flag.skip_attack = args.skip_attack - - -## stuff that I read on the matter - -https://dxiaochuan.medium.com/summary-of-python-config-626f2d5f6041 which -mentions https://github.com/apache/airflow/blob/175a1604638016b0a663711cc584496c2fdcd828/airflow/configuration.py#L233 -as an exemplar diff --git a/docs/original/developers/overall-plan.md b/docs/original/developers/overall-plan.md deleted file mode 100644 index b61fd45b0..000000000 --- a/docs/original/developers/overall-plan.md +++ /dev/null @@ -1,107 +0,0 @@ -# the big honking duo feature - -We developing larger-scale changes in the work-branch called `shenshaw26/duo`. -The goal is to migrate features into twosixlabs/armory as they are tested and -GARD developers are updated. Keeping it is a separate branch which keeps closely -_tracked to_ develop using frequent merges so that merges _into_ develop -can be done opportunistically. - -Although the overarching design is being worked on, this outlines some of the -major directions for discussion and review. Most sections of this note will -grow over the development effort to become their own design documents - -# the launcher - -A large part of what armory does is hoist up an execution environment and -populate it with data and model imports. - -There is a natural cleave point in `Evaluator._run_config` where all execution -is delegated to a new `python -m armory.scenarios.main` which should have all -setup pushed to the upstream side of that point and all compute engine -activities must be pushed below the cleave. Once this has been done, the -launcher code can then be pulled off into pure-python launcher which requires -no ML framework libraries (tf, torch) or other platform (e.g. docker) present -to install - -Formalizing this cleave point and the structures passed across will dramatically -help test rig construction since they can be versionable dependency injectors -instead of state sprinkled throughout the file system, environment variables, and -command arguments. - -## argument processing - -There are two disjoint invocations of argparse in `__main__.py` and `scenarios/main.py`. -The latter is actually an RPC deserialize step, with a corresponding re-serialize -step nearby. - -# the Experiment object - -The activities of armory focus around the evaluation of a block of engine -parameters call the Experiment. The former versions talk (confusingly) about -the armory "config file" which is distinct from the `~/.armory/config` file which -can be serialized to/from JSON. There is now an Experiment which can be serialized -to YAML as a `.aexp` file. - -# the Configuration Tin - -The Experiment object represents an evaluation job description, the `ConfigurationTin` -tin represents the execution environment for an experiment. It is called a tin -because `config` and its lexically close synonyms have been tainted by the old -Experiment. So armory's first task is to create the tin from the various sources. -Once the tin is populated, the resources it requires can be acquired and experiment -is evaluated in that context. - -As with the Experiment we're moving from amorphous bags of JSON properties to -well structured Python classes. A clear example is: - - class ArmoryCredentials - github_token: str - s3_id: str - s3_secret: str - -# toward the Armory library - -There is a substantial part of this Armory rework devoted to changing the model of -armory operation from a framework to a Python library. Clean definition of internal -interfaces has been peeking out through the sections above. The Launcher becomes -a smaller, well-defined means of reading Experiment parameters and Configuration -flags and passing them to Evaluate leading to pseudo-code like: - - environment = get_configuration(tin-path) - experiment = read_experiment(path) - results = evaluate(environment, experiment) - -The first advantage is that armory evaluations are now composable and programmable -with standard Python. The open design question is how this obvious calling sequence -can be extended so that there are useful interactions that an evaluator could have -with the evaluation engine. But, even if we find no additional mechanisms, clearer -segmentation of the code into initialization and evaluation will make it more -comprehensible and maintainable. - -# testability - -Segregating the platform dependent and independent parts increases testability. -We have already been making some extant tests platform-independent, and -having pure functions like `evaluate(experiment, context)` only speeds this. - -This means, in addition to better testing, that developer tests become feasible -without building out new containers and all the time and complexity needed -to run them. A developer can run - - pytest -m quick - -to get a rapid check that no breaking changes were made. It is also easier -to write tests when you don't have to wait 30+ minutes for the CI system to -fire up so much infrastructure. - - -## things to think about more - -1. Should experiments contain platform/sysconfig parameters. For example, should - `sysconfig.mode=docker` belong in the experiment? Put another way, should any system - parameter (e.g. --gpus) be configurable at by default, experiment, environment or - command argument regardless of their natural locus. -2. Find an easy way for Launcher to pass the evaluation request to a container - running elsewhere. This actually gets us some pretty big benefit if it can be - done simply. Need to run 9 different naive variant tests? Send it to a cluster - and get your results in 1/9th the time. diff --git a/docs/original/docker.md b/docs/original/docker.md deleted file mode 100644 index e1813fe20..000000000 --- a/docs/original/docker.md +++ /dev/null @@ -1,309 +0,0 @@ -# Docker -Armory is intended to be a lightweight python package which standardizes all evaluations -inside a docker container. - - -## Images -There are two docker images that are currently published to dockerhub for every release of -the armory framework: - -1. `twosixarmory/armory:` -2. `twosixarmory/pytorch-deepspeech:` - -NOTE: as of Armory version 0.15.0, we no longer support or publish a `tf1` image. -If `tf1` functionality is needed, please use the `tf2` image and use `tf1` compatibility mode. - -We additionally publish a base image, `twosixarmory/base:latest`, from which the three main images are derived. -This is updated less frequently, and each release does not necessarily have a corresponding new base. - -When using `armory launch` or `armory exec` the framework specific arguments will -utilize one of these three primary images. - -When running `armory run ` the image launched will be whatever is -specified in the `docker_image` field. This enables users to extend our images -and run evaluations on an image that has all additional requirements for their defense. - -### Custom Images - -If you wish to utilize custom images for armory, these can be directly specified by -either the `"docker_image"` field of the [config file](configuration_files.md) -of `armory run ` or in the CLI of the `launch` and `exec` commands, -as in `run launch `. - -Note: since Armory executes commands on detached containers, the `CMD` of the Docker image -will be *ignored* and replaced with `tail -f /dev/null` to ensure that the container does not -exit while those commands are being executed. - -### Interactive Use - -As detailed [here](index.md), it is possible to run the armory docker container in an -interactive mode using the `--interactive` CLI argument on `launch` or `run` commands. -We recommend this for debugging purposes, primarily. - -When run, armory will output instructions for attaching to the container, similar to the following: -``` -*** In a new terminal, run the following to attach to the container: - docker exec -it -u 1001:1001 c10db6c70a bash -*** To gracefully shut down container, press: Ctrl-C -``` -Note that `c10db6c70a` in this example is the container ID, which will change each time the -command is run. The `1001:1001` represents a mapping of users into the container, and will change -between systems and users. As stated, pressing `Ctrl-C` in that bash terminal will shut -down the container. To attach to the container, run the given command in a different bash terminal. - -This will bring you into the docker container, and bring up a bash prompt there: -``` -$ docker exec -it -u 1001:1001 c10db6c70a bash -groups: cannot find name for group ID 1001 -I have no name!@c10db6c70a81:/workspace$ -``` -The groups error and the user name `I have no name!` may show up, depending on the host system, and -can be safely ignored. This is only due to host user not having a corresponding group ID inside -the container. - -Once inside the container, you should be able to run or import armory as required: -``` -I have no name!@c10db6c70a81:/workspace$ armory version -0.13.0 -I have no name!@c10db6c70a81:/workspace$ python -Python 3.7.6 (default, Jan 8 2020, 19:59:22) -[GCC 7.3.0] :: Anaconda, Inc. on linux -Type "help", "copyright", "credits" or "license" for more information. ->>> import armory ->>> -``` - -Please see [running_armory_scenarios_interactively.ipynb](../notebooks/running_armory_scenarios_interactively.ipynb) for a tutorial on running Armory interactively. - -Note: We do not recommend using `--interactive` mode for installing custom requirements. You may -run into permissions issues, as everything is installed as root, but the armory user is not run -as root, to prevent potential security issues. Instead, we recommend creating a custom Docker image, -as described above. - -## Building Images from Source -When using a released version of armory, docker images will be pulled as needed when -evaluations are ran. However if there are issues downloading the images (e.g. proxy) -they can be built from the release branch of the repo: -``` -git checkout -b r0.16.0 -bash docker/build-base.sh -python docker/build.py [--no-pull] -``` - -If possible, we recommend downloading the base image instead of building, which can be done by removing the `--no-pull` argument from `build.py`. - - -## Docker Volume Mounts -When launching an ARMORY instance several host directories will be mounted within the -docker container. Note, the host directory path for datasets, saved_models, and -outputs are configurable. To modify those directories simply run `armory configure`. -The defaults are shown below: - - -| Host Path | Docker Path | -|:----------: | :-----------: | -| os.getcwd() | /workspace | -| ~/.armory/datasets | /armory/datasets | -| ~/.armory/saved_models | /armory/saved_models | -| ~/.armory/outputs | /armory/outputs | - - -When using these paths in code, armory provides a programatic way to access these -directories. - -### PyTorch model persistent storage - -If you are using the Armory PyTorch container, published models from PyTorch Hub -will often need to be retieved from a remote source. To avoid re-download of -that data on each container run, these will be stored in the -`/armory/saved_models/pytorch` container directory which is normally mapped to -`~/.armory/saved_models` on the host as shown in the table above. - - -#### Utilizing the paths -``` -from armory import paths -runtime_paths= paths.runtime_paths() -runtime_paths.dataset_dir -runtime_paths.saved_model_dir -``` - - -## Using GPUs with Docker -Armory uses the nvidia runtime to use GPUs inside of Docker containers. - -### Config GPU usage - -This can be specified in JSON config files with "sysconfig" as follows: -``` - ... - "sysconfig": { - ... - "gpus": "7", - "use_gpu": true - } - ... -``` -The `use_gpu` flag takes a boolean true/false value, and specifies whether to use the gpu or default to cpu. -The `gpus` flag is optional, and is ignored if `use_gpu` is false. If `use_gpu` is true, it defaults to using all GPUs. - If present, the value should be a `,`-separated list of numbers specifying the GPU index in `nvidia-smi`. - For instance, `"gpus": "2,4,7"` would enable three GPUs with indexes 2, 4, and 7. - Setting the field to be `all` will enable use of all available gpus, i.e. `"gpus": "all"` will enable all GPUs. - -### Command line GPU usage - -When using the `armory` commands `run`, `launch`, or `exec`, you can specify or override the above -`use_gpu` and `gpus` fields in the config with the following command line arguments: -1) `--use_gpu` -This will enable gpu usage (it is False by default). -Using the `--gpus` argument will override this field and set it to True. - -2) `--gpus` -This will enable the specified GPUs, similar to the docker `--gpus` argument. -The argument of this must be one of the following: - a) `--gpus all` - use all GPUs - b) `--gpus #` - use the GPU with the specified number. Example: `--gpus 2` - c) `--gpus #,#,...,#` - use the GPUs from the comma-separated list. Example: `--gpus 1,3` -If `--gpus` is not specified, it will default to the config file if present for `run`, -and will default to `all` if not present in `run` or when using `launch` and `exec`. - -Examples: -``` -armory run scenario_configs/mnist_baseline.json --use-gpu -armory launch tf2 --gpus=1,4 --interactive -armory exec pytorch --gpus=0 -- nvidia-smi -``` - -### CUDA - -Armory docker images currently use CUDA 11.6 as the base image ( see [Dockerfile-Base](../docker/Dockerfile-base)) -and the TensorFlow versions we support require CUDA 10+. Previous versions of CUDA (e.g. CUDA<11.6) are not actively tested -by armory developers or CI tools. However, if previous versions of CUDA are needed, the following instructions should -provide a decent starting point. - -To use CUDA 10.2, you will need to rebuild the base image and the derived images with the following changes: -in [docker/Dockerfile-base](../docker/Dockerfile-base) change: -```bash -FROM nvidia/cuda:11.6.1-cudnn8-runtime-ubuntu20.04 -``` -to -```bash -FROM nvidia/cuda:10.2-cudnn8-runtime-ubuntu18.04 -``` -and then change `cudatoolkit=11.6 \` to `cudatoolkit=10.2 \`. - -Again, this is not actively tested, so it may require further modification of library dependencies to -work appropriately. Also, while PyTorch does support CUDA 9, we do not provide support in armory due to -TFDS dependencies and we do not recommend using versions less than the standard 11.6. - -## Docker Setup -Depending on the evaluation, you may need to increase the default memory allocation for -docker containers on your system. - -Linux does not limit memory allocation, but on Mac and Windows this defaults to 2 GB -which is likely insufficient. See the docker documentation to change this: -* [Mac](https://docs.docker.com/docker-for-mac/) -* [Windows](https://docs.docker.com/docker-for-windows/) - - -## Docker Image Maintenance -Since there are new docker images for every release of ARMORY, you may want to clean up -your docker image cache as you increase versions. - -To display the set of current images on your machine, you can run: -``` -docker images -``` -To delete images, see the docs for [docker rmi](https://docs.docker.com/engine/reference/commandline/rmi/). - - -### Docker Container Maintenance -In order to see the set of containers that are running, run: -``` -docker ps -``` -ARMORY will attempt to gracefully shut down all containers it launches; -however, certain errors may prevent shutdown and leave running containers. -To shut down these containers, please see the docs for -[docker stop](https://docs.docker.com/engine/reference/commandline/stop/) -and [docker kill](https://docs.docker.com/engine/reference/commandline/kill/). - -## Running without docker - -Armory has partial support for users wishing to run without docker. Currently, the -`armory run` command can be run without Docker in Linux environments. To run without -docker, either set the `docker_image` field to be null in the scenario -configuration json file, or call `armory run` with the --no-docker option. - -Armory can also download and use datasets without docker. To use the download command, -simply add the `--no-docker` option, which will skip downloading the images and -run it in host mode: -``` -armory download --no-docker -``` - -After datasets have been downloaded, they can be used outside of docker by setting -the pathing mode to host in python: -```python -from armory import paths -paths.set_mode("host") -from armory.data import datasets -ds = datasets.mnist() -x, y = next(ds) -``` - -### Environment setup -NOTE: The listing of libraries needed for Armory when run on host is available at -`pyproject.toml`. You will need to manually install the requirements in -that file that match your framework (TF2, PyTorch). - -# publishing a new base - -As of armory v0.15, there is a base docker image which is pushed to dockerhub -occasionally. The container description is in [Dockerfile-base](docker/Dockerfile-base) -and there is a tiny [build-base.sh](docker/build-base.sh) helper script. - -We do not currently have any verification tests for this build. -**TODO**: add validation tests and make this a CI deployment job, perhaps. - - -## docker credentials - -In the GARD Keeper Password manager is the password for twosixarmory on dockerhub. -Run - - docker login --username twosixarmory - -and give it the password when prompted. It should respond `Login Succeeded` - -## push the new image - -This step is "push to production": it changes the latest image on our official -repository, so has the potential to break all container builds by any armory -user anywhere. - -If you do discover a breaking change, the only fix is to push a new image, since -[dockerhub does not allow reversion](https://stackoverflow.com/questions/55475080/how-can-i-revert-my-last-push-on-hub-docker-com) - -There is a `--dry-run` option which allows you to see what commands would be run. -It's a good idea to run that first: - - bash docker/build-base.sh --dry-run --push - -When satisfied that you want that run: - - bash docker/build-base.sh --push - -Will tag the image properly and push it to dockerhub. There will be two -new tags created at https://hub.docker.com/r/twosixarmory/base - - twosixarmory/base:latest - twosixarmory/base:VERSION - -both with the same digest. - -You might want to end with - - docker logout - -to avoid accidental `docker push` commands from using the shared account. diff --git a/docs/original/docker/.dockerignore b/docs/original/docker/.dockerignore deleted file mode 100644 index c47d00e8a..000000000 --- a/docs/original/docker/.dockerignore +++ /dev/null @@ -1,39 +0,0 @@ -# ignore .conda, etc. -.* - -# Allowing .git -!.git/ - -# Ensure all git files are present. Otherwise, armory will be "dirty" inside container, which will change the version -!.dockerignore -!.flake8 -!.github/ -!.gitignore -!.yamllint - -# ignore large directories -datasets/ - -# ignore temp directories -outputs/ -dist/ -tmp/ - -# Environments -.env -.venv -env/ -venv/ -ENV/ -env.bak/ -venv.bak/ -venv* - -# Byte-compiled / optimized / DLL files -__pycache__/ -*.pyc -*.py[cod] -*$py.class - -# mypy -.mypy_cache/ diff --git a/docs/original/docker/Dockerfile-armory b/docs/original/docker/Dockerfile-armory deleted file mode 100644 index 5b12f26e5..000000000 --- a/docs/original/docker/Dockerfile-armory +++ /dev/null @@ -1,136 +0,0 @@ -########################################################################################## -# -# ARMORY Baseline Docker Image -# -# This File contains the baseline image for Armory docker images. All framework -# based images should inhereit from this image using: -# FROM twosixlabs/armory-baseline AS armory-baseline -# -########################################################################################## - -FROM nvidia/cuda:11.6.2-cudnn8-runtime-ubuntu20.04 - -# pip Configuration - https://pip.pypa.io/en/stable/user_guide/#config-file -ARG PIP_DISABLE_PIP_VERSION_CHECK=1 -ARG PIP_NO_CACHE_DIR=1 - -# Temporary fix for broken nvidia package checksum -# RUN rm -f /etc/apt/sources.list.d/nvidia-ml.list - -# Basic Apt-get Bits -RUN apt-get -y -qq update && \ - DEBIAN_FRONTEND=noninteractive \ - apt-get install -y \ - wget \ - vim \ - build-essential \ - git \ - curl \ - libgl1-mesa-glx \ -# libglib2.0-0 \ - && rm -rf /var/lib/apt/lists/* -# libgl1-mesa-glx is needed for cv2 (opencv-python) - -# Install Conda -RUN wget --quiet https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh -O ~/miniconda.sh && \ - /bin/bash ~/miniconda.sh -b -p /opt/conda && \ - rm ~/miniconda.sh && \ - /opt/conda/bin/conda clean -tipsy && \ - ln -s /opt/conda/etc/profile.d/conda.sh /etc/profile.d/conda.sh -# ln -s /opt/conda/etc/profile.d/conda.sh /etc/profile.d/conda.sh && \ -# echo ". /opt/conda/etc/profile.d/conda.sh" >> ~/.bashrc && \ -# echo "conda activate base" >> ~/.bashrc && \ -# echo 'alias ll="ls -al"' >> ~/.bashrc - -ENV PATH=/opt/conda/bin:$PATH - -# TensorFlow requirement -ENV LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/opt/conda/lib/ - -# NOTE: using mamba because conda fails when trying to solve for environment -RUN conda install -c conda-forge -n base mamba \ - && conda clean --all - - -WORKDIR /armory-repo - -COPY environment.yml /armory-repo/ -# NOTE: This COPY command is filtered using the `.dockerignore` file -# in the root of the repo. -COPY ./ /armory-repo - - -RUN mamba env update -f environment.yml -n base --prune \ - && mamba clean --all - -#RUN /opt/conda/bin/conda env update -f environment.yml --prune \ -# && /opt/conda/bin/conda clean --all -# NOTE: with conda version 5, will need to set channel priority to flexible (as strict will become default) - -# NOTE: Armory requirements and ART requirements are installed here to make patch updates fast and small -RUN echo "Installing TensorFlow and ART/Armory requirements via pip" -RUN /opt/conda/bin/pip install --no-cache-dir \ - tensorflow-datasets==4.6 \ - tensorflow==2.10 \ - tensorboardx \ - boto3 \ - opencv-python \ - ffmpeg-python \ - pytest \ - loguru \ - docker \ - jsonschema \ - requests \ - pydub \ - transformers \ - six \ - setuptools \ - tqdm -# transformers is used for the Entailment metric only -# pydub required for ART mp3 defense - - -## Deepspeech Requirements -RUN pip install git+https://github.com/romesco/hydra-lightning/\#subdirectory=hydra-configs-pytorch-lightning - -RUN echo "Updating pip" && \ - pip install --upgrade pip && \ - echo "Building Armory from local source" && \ - pip install --no-compile --editable '.[developer]' && \ - echo "Configuring Armory..." && \ - armory configure --use-default && \ - echo "Cleaning up..." && \ - rm -rf /armory-repo/.git - -RUN pip install \ - git+https://github.com/ifzhang/ByteTrack.git \ - thop \ - lap \ - Cython && \ - # Requires cython for install, so will fail if run in the same pip install as cython - pip install cython-bbox - - -WORKDIR /workspace - - -# ------------------------------------------------------------------ -# DEVELOPER NOTES: -# ------------------------------------------------------------------ -# TODO: determine if this environment setup is needed -# $ ENV LD_LIBRARY_PATH="${LD_LIBRARY_PATH}:/usr/local/cuda/lib64" - -# NOTE: -# - pytorch-lightning >= 1.5.0 will break Deep Speech 2 -# - torchmetrics >= 0.8.0 will break pytorch-lightning 1.4 -# - hydra-lightning installs omegaconf -# - google-cloud-storage needed for checkpoint.py import -# - only sox python bindings are installed; underlying sox binaries not needed - -# NOTE: Listed dependencies of PyTorch Deep Speech 2, but do not appear -# to be used for inference (only for training), they are not installed: -# - torchelastic -# - wget -# - flask -# - fairscale -# ------------------------------------------------------------------ \ No newline at end of file diff --git a/docs/original/docker/README.md b/docs/original/docker/README.md deleted file mode 100644 index f03934ba4..000000000 --- a/docs/original/docker/README.md +++ /dev/null @@ -1,90 +0,0 @@ -# Docker -Armory is intended to be a lightweight python package which standardizes all evaluations -inside a docker container. - -## Updates - - As of Armory version 0.16.0 the `docker/build.sh` script has been deprecated. - - Standardized python build script: `python docker/build.py --help` - - As of Armory version 0.15.0, we no longer support or publish a `tf1` image. - - If `tf1` functionality is needed, please use the `tf2` image and use `tf1` compatibility mode. - - -### Custom Images -If you wish to utilize custom images for armory, these can be directly specified by -either the `"docker_image"` field of the [config file](configuration_files.md) -of `armory run ` or in the CLI of the `launch` and `exec` commands, -as in `run launch `. - -Note: since Armory executes commands on detached containers, the `CMD` of the Docker image -will be *ignored* and replaced with `tail -f /dev/null` to ensure that the container does not -exit while those commands are being executed. - - -## Building Images from Source -When using a released version of armory, docker images will be pulled as needed when -evaluations are ran. However if there are issues downloading the images (e.g. proxy) -they can be built from the release branch of the repo: -``` -git checkout -b r0.16.0 -bash docker/build-base.sh -python docker/build.py [--no-pull] -``` - -If possible, we recommend downloading the base image instead of building, which can be done by removing the `--no-pull` argument from `build.py`. - - -## Docker Volume Mounts -Host directory path for datasets, saved_models, and outputs are configurable. To modify those directories simply run `armory configure`. -The defaults are shown below: - - -| Host Path | Docker Path | -|:----------: | :-----------: | -| os.getcwd() | /workspace | -| ~/.armory/datasets | /armory/datasets | -| ~/.armory/saved_models | /armory/saved_models | -| ~/.armory/outputs | /armory/outputs | - - -When using these paths in code, armory provides a programatic way to access these -directories. - - -## Using GPUs with Docker -Armory uses the nvidia runtime to use GPUs inside of Docker containers. - -### CUDA -Armory docker images currently use CUDA 11.6 as the base image ( see [Dockerfile-Base](../docker/Dockerfile-base)) -and the TensorFlow versions we support require CUDA 10+. Previous versions of CUDA (e.g. CUDA<11.6) are not actively tested -by armory developers or CI tools. However, if previous versions of CUDA are needed, the following instructions should -provide a decent starting point. - -To use CUDA 10.2, you will need to rebuild the base image and the derived images with the following changes: -in [docker/Dockerfile-base](../docker/Dockerfile-base) change: -```bash -FROM nvidia/cuda:11.6.1-cudnn8-runtime-ubuntu20.04 -``` -to -```bash -FROM nvidia/cuda:10.2-cudnn8-runtime-ubuntu18.04 -``` -and then change `cudatoolkit=11.6 \` to `cudatoolkit=10.2 \`. - -Again, this is not actively tested, so it may require further modification of library dependencies to -work appropriately. Also, while PyTorch does support CUDA 9, we do not provide support in armory due to -TFDS dependencies and we do not recommend using versions less than the standard 11.6. - - -## Docker Setup -Depending on the evaluation, you may need to increase the default memory allocation for -docker containers on your system. - -Linux does not limit memory allocation, but on Mac and Windows this defaults to 2 GB -which is likely insufficient. See the docker documentation to change this: -* [Mac](https://docs.docker.com/docker-for-mac/) -* [Windows](https://docs.docker.com/docker-for-windows/) - -### Environment setup -NOTE: The listing of libraries needed for Armory when run on host is available at -`pyproject.toml`. You will need to manually install the requirements in -that file that match your framework (TF1, TF2, PyTorch). diff --git a/docs/original/docker/build-base.sh b/docs/original/docker/build-base.sh deleted file mode 100644 index db832a631..000000000 --- a/docs/original/docker/build-base.sh +++ /dev/null @@ -1,44 +0,0 @@ -#!/usr/bin/env bash -set -e - -usage() { echo "usage: $0 [--dry-run] [--push]" 1>&2; exit 1; } - -dryrun="${ARMORY_DRYRUN:-}" -push="${ARMORY_PUSH:-}" - -while [ "${1:-}" != "" ]; do - case "$1" in - -n|--dry-run) - echo "dry-run requested. not building or pushing to docker hub" - dryrun="echo" ;; - --push) - push=true ;; - *) - usage ;; - esac - shift -done - -echo "Building the base image locally" -$dryrun docker build --force-rm --file ./docker/Dockerfile-armory -t twosixarmory/armory:latest --progress=auto . - -if [[ -z "$push" ]]; then - echo "" - echo "If building the framework images locally, use the '--no-pull' argument. E.g.:" - echo " python docker/build.py all --no-pull" - exit 0 -fi - -tag=$(python -m armory --version) -echo tagging twosixarmory/base:latest as $tag for dockerhub tracking -$dryrun docker tag twosixarmory/base:latest twosixarmory/base:$tag - -echo "" -echo "If you have not run 'docker login', with the proper credentials, these pushes will fail" -echo "see docs/docker.md for instructions" -echo "" - -# the second push should result in no new upload, it just tag the new image as -# latest -$dryrun docker push twosixarmory/armory:$tag -$dryrun docker push twosixarmory/armory:latest diff --git a/docs/original/faqs.md b/docs/original/faqs.md deleted file mode 100644 index 3811314fb..000000000 --- a/docs/original/faqs.md +++ /dev/null @@ -1,67 +0,0 @@ -# Frequently Asked Questions - -### What do the armory version strings mean? - -As of Armory 0.16 we are using a newer mechanism for versioning which is -intended to help armory developers and some users better record the precise -code commit used in a build. - -In the normal case, as a regular armory user, - - pip install armory-testbed - armory --version - -will yield an undecorated version number like `0.16.0`. This version also -gets recorded in armory output files, so if you are running a clean release version, -you won't see anything different. - -If you modify the armory source and then rebuild it, the version will contain a -git commit id. For example, my most recent build when I modified my local source -was - - 0.16.0.builda7492e4 - -This shows that the build was made on a 0.16.0 base with the most recent commit -being `456abc`. This is useful for developers who want to know exactly what code -produced this build. It also allows recreation of a prior version if needed by - - git checkout a7492e4 - pip install -e . - -#### Why do Datasets return NumPy Arrays? -Currently, the ART toolbox only accepts NumPy arrays as inputs to attacks, defenses -and model fitting. It is understood that this is an inefficient way to utilize data -since it requires a conversion from FrameworkTensor -> ndarray -> FrameworkTensor. - -Framework specific attacks / defenses are on the roadmap for ART and when available we -will switch to having PyTorch or TensorFlow data generators. - - -#### How/where do I perform dataset preprocessing when running a scenario? -As of Armory 0.12, dataset preprocessing should be performed inside the model. The functions -to retrieve datasets in [armory/data/datasets.py](../armory/data/datasets.py) do each accept -a `preprocessing_fn` kwarg that can used when loading datasets outside the context of a scenario. -However, this kwarg is by default set to the canonical preprocessing function for each dataset and -is not configurable when running Armory scenarios. - - -#### Why are datasets loaded with non-configurable "canonical" preprocessing during Armory scenarios? -Standardizing the dataset format simplifies the measuring of perturbation distance and -allows for easier comparison across different defenses and attacks. - - -#### Accessing underlying wrapped model -There are many times when creating a scenario you may want to access the underlying -framework model that has been wrapped as an ART classifier. In the future we'll have -a convenience method to access the models through an ART api, but in the short term they -can be accessed as follows: - -KerasWrapper: -``` -underlying_model = wrapped_classifier._model -``` - -PyTorchWrapper: -``` -underlying_model = wrapped_classifier._model._model -``` diff --git a/docs/original/getting_started.md b/docs/original/getting_started.md deleted file mode 100644 index 02a643170..000000000 --- a/docs/original/getting_started.md +++ /dev/null @@ -1,124 +0,0 @@ -# Getting Started - -## Installation -Armory can be installed from PyPi: -``` -pip install armory-testbed[framework-flavor] -``` - -Where `framework-flavor` is one of `tensorflow`, `pytorch` or `deepspeech` -as described below in [the armory flavors](#the-armory-flavors). - -When a user runs a given configuration file, the necessary docker image, datasets and -model weights will be pulled as needed. We do have convenience functions to download -all images, datasets and model weights for a scenario set release. This can take a -while, so you may want to run it overnight: -``` -git clone https://github.com/twosixlabs/armory-example.git -cd armory-example -# First set of examples: -armory download scenario_download_configs/scenarios-set1.json -# Second set of scenarios: -armory download scenario_download_configs/scenarios-set2.json -``` -If you are not using Docker, then add `--no-docker`: -``` -armory download scenario_download_configs/scenarios-set*.json --no-docker -``` - -If you want to download with a specific image, use: -``` -armory download --docker-image scenario_download_configs/scenarios-set*.json -``` - -## Baseline models -The armory package contains several framework specific baseline models that can be used -during evaluation. Please see our documentation on baseline models for more information -about what is available and what pretrained weights can be pulled from S3: - -[Baseline Model Docs](baseline_models.md) - -## Running an evaluation -Evaluations are typically run through the use of configuration files. See the -[config file documentation](/docs/configuration_files.md) for information regarding the -schema and what the fields refer to. - -To run a configuration: -``` -git clone https://github.com/twosixlabs/armory-example.git -cd armory-example -armory run official_scenario_configs/cifar10_baseline.json -``` - -## External Repos -You may want to include code from an external repository that is outside of your -current working directory project. This is fully supported by Armory and more -information can be found in the [external repo documentation](/docs/external_repos.md). - -## the armory flavors - -Armory supports multiple frameworks: - - - tensorflow - - pytorch - - deepspeech - -In releases prior to 0.16, there was a complex set of `*-requirements.txt` files -that were needed to provision the python environment for the various frameworks. -As of Armory 0.16, these have all been consolidated into the standard -`pyproject.toml` at the repository root. - -We now use the optional-dependencies feature of pyproject which requires -the selection of a flavor to be specified at install time. For example: - - pip install armory-testbed - -installs no framework libraries so will fail to run any framework dependent code. Future -armory releases may use this flavorless base. To install the tensorflow flavor: - - pip install armory-testbed[tensorflow] - -which installs the libraries needed for tensorflow evaluations. Similarly, - - pip install armory-testbed[pytorch] - -or - - pip install armory-testbed[deepspeech] - -depending on the framework you want to use. We don't recommend trying to -install multiple frameworks at the same time as this may lead to dependency -conflicts. So - - pip install armory-testbed[tensorflow,pytorch] - -is unsupported and may not even install. - -## additional flavors - -You can freely add `jupyterlab` to the flavor list to as needed, for example - - pip install armory-testbed[tensorflow,jupyterlab] - -People developing armory will likely want to add the `developer` flavor to their -set: - - pip install armory-testbed[deepspeech,developer,jupyterlab] - -Developers who are creating new Armory datasets will need - - pip install armory-testbed[datasets-builder] - -## editable installs - -As before, the `--editable` flag can be used to install in editable mode -which is often useful for development. - -The `.` installation target is also supported, but even that requires -a flavor specification. That is, where you might have previously run - - pip install --editable . - -you now need to specify a flavor: - - pip install --editable .[pytorch] diff --git a/docs/original/index.md b/docs/original/index.md deleted file mode 100644 index 13e9933f8..000000000 --- a/docs/original/index.md +++ /dev/null @@ -1,98 +0,0 @@ -# Welcome to Armory Testbed - -## Overview - -ARMORY is a test bed for running scalable evaluations of adversarial defenses. -Configuration files are used to launch local or cloud instances of the ARMORY docker -containers. Models, datasets, and evaluation scripts can be pulled from external -repositories or from the baselines within this project. - -Our evaluations are created so that attacks and defenses may be -interchanged. To do this we standardize all attacks and defenses as subclasses of -their respective implementations in IBM's [adversarial-robustness-toolbox](https://github.com/IBM/adversarial-robustness-toolbox) - - -## Usage - -There are three ways to interact with the armory container system. - -1) `armory run` - -* `armory run `. -This will run a [configuration file](configuration_files.md) end to end. Stdout -and stderror logs will be displayed to the user, and the container will be removed -gracefully upon completion. Results from the evaluation can be found in your output -directory. - -* `armory run --interactive`. -This will launch the framework-specific container specified in the -configuration file, copy the configuration file into the container, and provide -the commands to attach to the container in a separate terminal and run the -configuration file end to end while attached to the container. Similar to -non-interactive mode, results from the evaluation can be found in the output -directory. To later close the interactive container simply run CTRL+C from the -terminal where this command was ran. Please see [running_armory_scenarios_interactively.ipynb](../notebooks/running_armory_scenarios_interactively.ipynb) for a tutorial on running Armory interactively. - -2) `armory launch` - -* `armory launch --interactive`. -This will launch a framework specific container, with appropriate mounted volumes, for -the user to attach to for debugging purposes. A command to attach to the container will -be returned from this call, and it can be ran in a separate terminal. To later close -the interactive container simply run CTRL+C from the terminal where this command was -ran. - -* `armory launch --jupyter`. -Similar to the interactive launch, this will spin up a container for a specific -framework, but will instead return the web address of a jupyter lab server where -debugging can be performed. To close the jupyter server simply run CTRL+C from the -terminal where this command was ran. - -3) `armory exec` - -* `armory exec -- `. -This will run a specific command within a framework specific container. A notable use -case for this would be to run test cases using pytest. After completion of the command -the container will be removed. - -To use custom docker images with `launch` or `exec`, replace `` with its -full name: ``. For use with `run`, you will need to modify the -[configuration file](configuration_files.md). - -Note: Since ARMORY launches Docker containers, the python package must be ran on -system host (i.e. not inside of a docker container). - -For more information, see [command line usage](command_line.md). - -### Example usage: -``` -pip install armory-testbed -armory configure -git clone https://github.com/twosixlabs/armory-example.git -cd armory-example -armory run official_scenario_configs/cifar10_baseline.json -``` - -### What is available in the container: -All containers have a pre-installed armory package installed so that baseline models, -datasets, and scenarios can be utilized. - -Additionally, volumes (such as your current working directory) will be mounted from -your system host so that you can modify code to be ran, and retrieve outputs. -For more information on these mounts, please see our [Docker documentation](docker.md#docker-volume-mounts) - -## Scenarios -Armory provides several baseline threat-model scenarios for various data modalities. -When running an armory configuration file, the robustness of a defense will be -evaluated against that given scenario. For more information please see our -[Scenario Documentation](scenarios.md). - -## Dataset licensing -See [dataset_licensing.md](dataset_licensing.md) for details related to the licensing of datasets. - -## Acknowledgment -This material is based upon work supported by the Defense Advanced Research Projects -Agency (DARPA) under Contract No. HR001120C0114. Any opinions, findings and -conclusions or recommendations expressed in this material are those of the author(s) -and do not necessarily reflect the views of the Defense Advanced Research Projects -Agency (DARPA). diff --git a/docs/original/instrumentation_examples.md b/docs/original/instrumentation_examples.md deleted file mode 100644 index 5488920c6..000000000 --- a/docs/original/instrumentation_examples.md +++ /dev/null @@ -1,181 +0,0 @@ -# Armory Instrumentation Examples: Measuring Experiment Artifacts Using Probes and Meters -For an introduction to `Probe`s and `Meter`s, please refer to [Measurement Overview](./metrics.md#instrumentation). We assume the user is capturing artifacts from the model or attack and wishes to use `Probe`s and `Meter`s to monitor certain variables within the code. - -Recall the steps for a minimal working example (in [Measurement Overview](./metrics.md#instrumentation)): -1. Create `Probe` via `get_probe(name)` -2. Place `Probe` actions -3. Create `Meter` with processing functions that take input from created `Probe` -4. Connect `Meter` to `Hub` via `get_hub().connect_meter(meter)` - -The examples will show how each of these steps are accomplished. - -## Example 1: Measuring a Model Layer's Output -### User Story -I am interested in the layer output from the second `relu` activation of a `forward` method located in `armory/baseline_models/pytorch/cifar.py`. -### `Probe` Example Code -The code below is an example of how to accomplish steps 1 and 2 (note the lines of code with `# added` comments at the end) for a model code that the user is modifying. -```python -""" -CNN model for 32x32x3 image classification -""" -... - -from armory.instrument import get_probe # added -probe = get_probe("my_model") # added - -class Net(nn.Module): - ... - - def forward(self, x: torch.Tensor) -> torch.Tensor: - x = x.permute(0, 3, 1, 2) # from NHWC to NCHW - x = self.conv1(x) - x = F.relu(x) - x = F.max_pool2d(x, 2) - x = self.conv2(x) - x = F.relu(x) - x_out = x.detach().cpu().numpy() # added - probe.update(layer_output=x_out) # added - x = F.max_pool2d(x, 2) - x = torch.flatten(x, 1) - x = self.fc1(x) - x = F.relu(x) - x = self.fc2(x) - output = F.log_softmax(x, dim=1) - return output - -... -``` - -#### Step 1 -After importing `get_probe`, `probe = get_probe("my_model")` creates a `Probe` object with the name `"my_model"`, which is what the user can refer to later to apply processing functions through a `Meter` object. - -#### Step 2 -`x_out = x.detach().cpu().numpy()` is taking the layer output of interest (second `relu` activation output) and converting the tensor to `numpy` array on the CPU, which will be passed to `probe`. An updated value of `x_out` is stored in `layer_output` via `probe.update(layer_output=x_out)`. Like the `Probe` name `"my_model"`, `layer_output` can be referenced by the user later to apply additional processing functions through a `Meter` object. - -### `Meter` Example Code -Now that a `Probe` instance has been created, we need to create a `Meter` object to accept any updated values from `Probe` and apply further processing that the user desires. We can create the `Meter` in a function added to a local Python script we'll name `user_init_script.py`. In [Config Setup](#config-setup) shortly below, we'll show how to ensure this code is run during scenario initialization. -```python -from armory.instrument import get_hub, Meter - -def set_up_meter(): - meter = Meter( - "my_arbitrary_meter_name", lambda x: x, "my_model.layer_output" - ) - get_hub().connect_meter(meter) -``` -#### Step 3 -In this particular example, the `Meter` accepts 3 inputs: a meter name, a metric/function for processing, and a argument name to pass the metric/function. -- The meter name (`"my_arbitrary_meter_name"`) can be arbitrary within this context -- For the scope of this document, we only consider simple `Meter`s with the identity function as a metric i.e. `Meter` will record variables monitored by `Probe` as-is (thus `lambda x: x`) -- The argument passed to the metric/function follows a `.`-separated format (`"my_model.layer_output"`), which needs to be consistent with `Probe` setup earlier: - - `my_model` matches input in `probe = get_probe("my_model")` - - `layer_output` matches variable name in `probe.update(layer_output=x_out)` - -#### Step 4 -For the scope of this document, we don't dwell on what `armory` is doing with `get_hub().connect_meter(meter)` other than to mention this step is necessary for establishing the connection between `meter` created in `armory/user_init_script.py` and `probe` created in the modified version of `armory/baseline_models/pytorch/cifar.py`. - -### Config Setup -Last but not least, the config file passed to `armory run` needs to be updated for these changes to take effect, which is accomplished by adding the `"user_init"` block (please refer to [User Initialization](./scenarios.md#user-initialization) for more details): -```json -... - "user_init": { - "module": "user_init_script", - "name": "set_up_meter" - }, -... -``` -This will prompt armory to run `set_up_meter` in `user_init_script.py` before anything else is loaded for the scenario. - -## Example 2: Measuring Attack Artifact -### User Story -I defined a custom attack with `CARLADapricotPatch` in `armory/custom_attack.py`, and I am interested in the patch after ***every iteration***, which is generated by `CARLADapricotPatch._augment_images_with_patch` and returned as an output. -### `Probe` Example Code -```python -from armory.art_experimental.attacks.carla_obj_det_patch import CARLADapricotPatch -from armory.instrument import get_probe -probe = get_probe("my_attack") - -class CustomAttack(CARLADapricotPatch): - def _augment_images_with_patch(self, **kwargs): - return_value = super()._augment_images_with_patch(**kwargs) - x_patch, patch_target, transformations = return_value - probe.update(attack_output=x_patch) - - return return_value -``` -#### Step 1 -This step is the same as before, except `Probe` name is set to`"my_attack"`, which is what the user can refer to later to apply processing functions through a `Meter` object. - -#### Step 2 -The only difference between `CustomAttack` and `CARLADapricotPatch` is that `_augment_images_with_patch` has been redefined to call on `CARLADapricotPatch._augment_images_with_patch` and then have `probe` update the value for `x_patch` that results from that call. An updated value of `x_patch` is stored in `attack_output` via `probe.update(attack_output=x_patch)`. Like the `Probe` name `"my_attack"`, `attack_output` can be referenced by the user later to apply additional processing functions through a `Meter` object. - -### `Meter` Example Code -As in [Example 1](#meter-example-code), we need to create a `Meter` object to accept any updated values from `Probe` and apply further processing that the user desires. We can create the `Meter` in a function added to a local Python script `user_init_script.py`. In [Config Setup](#config-setup-1) shortly below, we'll show how to ensure this code is run during scenario initialization. -```python -from armory.instrument import get_hub, Meter - -def set_up_meter(): - meter = Meter( - "my_arbitrary_meter_name", lambda x: x, "my_attack.attack_output" - ) - get_hub().connect_meter(meter) -``` -#### Step 3 -As before, the `Meter` accepts 3 inputs: a meter name, a metric/function for processing, and a argument name to pass the metric/function. -- The meter name (`"my_arbitrary_meter_name"`) can be arbitrary within this context -- Again, `Meter` will record variables monitored by `Probe` as-is (thus `lambda x: x`) -- The argument passed to the metric/function follows a `.`-separated format (`"my_attack.attack_output"`), which needs to be consistent with `Probe` setup earlier: - - `my_attack` matches input in `probe = get_probe("my_attack")` - - `attack_output` matches variable name in `probe.update(attack_output=x_patch)` - -#### Step 4 -Again, `get_hub().connect_meter(meter)` is necessary for establishing the connection between `meter` created in `armory/user_init_script.py` and `probe` created in `armory/custom_attack.py`. - -### Config Setup -Last but not least, the config file passed to `armory run` needs to be updated for these changes to take effect, which is accomplished by adding the `"user_init"` block (please refer to [User Initialization](./scenarios.md#user-initialization) for more details): -```json -... - "user_init": { - "module": "user_init_script", - "name": "set_up_meter" - }, -... -``` -This will prompt armory to run `set_up_meter` in `user_init_script.py` before anything else is loaded for the scenario. - -## Saving Results -By default, outputs from `Meter`s will be saved to the output `json` file after `armory run`. Whether this suffices for the user depends on what the user is trying to measure. - -Users who have tried the examples in this document, however, may run into some of the following warning logs: -> 2022-12-16 19:34:36 30s WARNING armory.instrument.instrument:_write:856 record (name=my_arbitrary_meter_name, batch=0, result=...) size > max_record_size 1048576. Dropping. - -Outputs are saved to a `json` file because of a default `ResultWriter` class tied to the `Meter` class, which has a `max_record_size` limit for each record. Any record that exceeds `max_record_size` will not save to the `json` file. That the outputs exceed a size limit also suggests that a `json` file may not be the best file type to save to. To work around these behaviors, we can define a new `Writer` subclass (`ResultWriter` is also a `Writer` subclass) to work with our examples that does not have a size limit and will save to another filetype, such as a `png` file, since we are saving data for an image. Below is an updated `user_init_script.py` for Example 2 with a new `ImageWriter` class, which uses the `export` method of `ObjectDetectionExporter` to save an image, and a `set_up_meter_writer` function that will be executed with the `user_init` block: -```python -from armory.instrument import get_hub, Meter, Writer -from armory.instrument.export import ObjectDetectionExporter - -class ImageWriter(Writer): - def __init__(self, output_dir): - super().__init__() - self.output_dir = output_dir - self.iter_step = 0 - self.current_batch_index = 0 - self.exporter = ObjectDetectionExporter(self.output_dir) - - def _write(self, name, batch, result): - if batch != self.current_batch_index: - self.current_batch_index = batch # we are on a new batch - self.iter_step = 0 # restart iter_step count - basename = f"{name}_batch_{batch}_iter_{self.iter_step}" - # assume single image per batch: result[0] - self.exporter.export(x = result[0], basename = basename) - self.iter_step += 1 # increment iter_step - -def set_up_meter_writer(): - meter = Meter( - "my_attack_identity", lambda x: x, "my_attack.attack_output" - ) - writer = ImageWriter(output_dir = get_hub().export_dir) - meter.add_writer(writer) - get_hub().connect_meter(meter, use_default_writers=False) -``` \ No newline at end of file diff --git a/docs/original/integrate_tensorflow_datasets.md b/docs/original/integrate_tensorflow_datasets.md deleted file mode 100644 index 1d692f040..000000000 --- a/docs/original/integrate_tensorflow_datasets.md +++ /dev/null @@ -1,18 +0,0 @@ -# Instructions to Integrate TFDS Datasets - -1. Get the name, version number of the Tensorflow Dataset, and optionally the config: "name[/config]:version_number", where the brackets denote optional text. -2. Set the environmental variables ARMORY_PRIVATE_S3_ID and ARMORY_PRIVATE_S3_KEY to the appropriate keys with write access to the Armory S3 bucket. -3. From a locally cloned version of armory, on a new branch, run: -``` -python -m armory exec pytorch -- python -m armory.data.integrate_tfds name[/config]:version -``` -where the brackets denote optional text. - -The script will download and process the TFDS dataset, generate TF Records files, create a tarball, and upload the tarball to S3. It also will create a S3 checksum file in ```armory/data/cached_s3_checksums/{name}.txt``` - -4. Run ```git status``` to confirm the S3 checksum file was generated and to see the path of the template file. -5. Manually put the template code from ```TEMPLATE_{name}.txt``` in ```armory/data/datasets.py```. Create a context object that contains metadata and a preprocessing function that does appropriate integrity checks/input normalizing. See for example the [canonical fixed-size image preprocessing function](https://github.com/twosixlabs/armory/blob/deb7a469bf4a7497d14fdd87eba6417b5e44589f/armory/data/datasets.py#L617-L631) which checks the shapes of an image, and renormalizes it to be in the appropriate range defined by the context object (typically 0.0-1.0) with a standard type. See the documentation on dataset [preprocessing](https://armory.readthedocs.io/en/latest/datasets/#preprocessing) for more details. -6. [Optional] Add the dataset to the [SUPPORTED_DATASETS](https://github.com/twosixlabs/armory/blob/deb7a469bf4a7497d14fdd87eba6417b5e44589f/armory/data/datasets.py#L1498-L1511) dictionary by adding a key with the dataset's name and value of the dataset function from the template code. -7. [Optional] Create a continuous integration test for the dataset in ```tests/test_docker/test_dataset.py```, possibly using ```pytest.skip```. -8. Commit the changes to the branch on your fork of the Armory repo. -9. Open a PR to integrate the dataset. diff --git a/docs/original/library/README.md b/docs/original/library/README.md deleted file mode 100644 index 6cca959b7..000000000 --- a/docs/original/library/README.md +++ /dev/null @@ -1,29 +0,0 @@ -# Armory as a Library - -## strategy for decomposition - -1. Define the Experiment class which 1:1 maps from config.yaml -2. Pare down the function of Scenario as in #Scenario below -3. Flesh out the Experiment block class (e.g. Attack) with code pulled out of - Scenario - -## Experiment - -Experiment = json.load(config.json) - -This operation allows us to keep the concept of a config file, but becomes an -argument to Loader/Engine/etc. - - class Experiment: - load_from_file(path) - __init__(**kwargs) - -See [experiment.py](docs/experiment.py) for a sample implementation of the -various blocks of class Experiment. - -## Scenario - -Should be the bit of current armory.Scenario which is not related to loading -models, attacks, datasets, etc. This means that we need to method-by-method -figure out what is actually the Scenario and move everything else out of that -God object. diff --git a/docs/original/library/experiment.py b/docs/original/library/experiment.py deleted file mode 100644 index d6d5406fe..000000000 --- a/docs/original/library/experiment.py +++ /dev/null @@ -1,106 +0,0 @@ -# flake8: noqa -# psuedocode from the tiga days showing the intent of the Experiment class - -from importlib import import_module -import json -import os - -import yaml - -from armory.logs import log -from armory.utils import parse_overrides - - -class Attack: - name: str - module: str - knowledge: str - kwargs: dict - type: str = None - - -class Dataset: - name: str - module: str - framework: str - batch_size: int - - -class Defense: - name: str - type: str - module: str - kwargs: dict - - -class Metric: - means: bool - perturbation: str - record_metric_per_sample: bool - task: list - - -class Model: - name: str - module: str - weights_file: str = None - wrapper_kwargs: dict - model_kwargs: dict - fit_kwargs: dict - fit: bool - - -class Scenario: - function_name: str - module_name: str - kwargs: dict - - -class SystemConfiguration: - docker_image: str = None - gpus: str = None - external_github_repo: str = None - output_dir: str = None - output_filename: str = None - use_gpu: bool = False - - -class MetaData: - name: str - author: str - description: str - - -class Poison: - pass - - -class Experiment: - _meta: MetaData - poison: Poison = None - attack: Attack = None - dataset: Dataset - defense: Defense = None - metric: Metric = None - model: Model - scenario: Scenario - # sysconfig: SystemConfiguration = None - - # def save(self, filename): - # with open(filename, "w") as f: - # f.write(self.json()) - - -class Experiment(object): - """Execution Class to `run` armory experiments""" - - def __init__(self, experiment_, environment_): - log.info(f"Constructing Experiment using : \n{experiment_}") - self.exp_pars = experiment_ - self.env_pars = environment_ - log.info(f"Importing Scenario Module: {self.exp_pars.scenario.module_name}") - self.scenario_module = import_module(self.exp_pars.scenario.module_name) - log.info(f"Loading Scenario Function: {self.exp_pars.scenario.function_name}") - self.scenario_fn = getattr( - self.scenario_module, self.exp_pars.scenario.function_name - ) diff --git a/docs/original/logging.md b/docs/original/logging.md deleted file mode 100644 index b497fef6f..000000000 --- a/docs/original/logging.md +++ /dev/null @@ -1,128 +0,0 @@ -# logging facilities and options in armory - -Because the primary communication between armory and the user happens by way of logs, -the system and configuration options are broad, with reasonable defaults so that it does -the right thing to start. - -## the armory logging api - -In order to use the armory logger, all you need to do is import it: - - from armory.logs import log - -The `log` object is the primary interface to the module and supports the following -standard functions: - - log.debug - log.info - log.warning - log.error - log.critical - -The armory logger also adds two new levels - - log.trace - even more verbose than debug - log.success - report that something completed ok - -All these functions take one string argument - - log.success(f'uploaded {file} to {server}') - -There are two additional log levels without a standard function: - - `"PROGRESS"` - for determining whether to log progress for downloads/uploads - `"METRIC"` - for logging metric results - -The explicit ordering of these log levels are: -``` -TRACE = 5 -DEBUG = 10 -PROGRESS = 15 -INFO = 20 -METRIC = 24 -SUCCESS = 25 -WARNING = 30 -ERROR = 40 -CRITICAL = 50 -``` - -The armory logger upon import is pre-initialized and requires no configuration. So as a -user of the library, that's all you need to know. - -## logger destinations - -The armory.logs system always logs to the console, this is initialized at import -time. The module also writes to two files called - - colored-log.txt - armory-log.txt - -where the first is a direct duplicate of the console, and the second is identical -but without ansi color escapes for easier parsing. These files want to be -placed in the armory `output_dir` in the same timestamped directory that holds -the output file. However, that directory name isn't known until at armory start -time so the log files are created in the configured `output_dir` at the start. - -When armory knows the name of that timestamped directory it calls - - armory.logs.make_logfiles(timestamp_directory) - -TODO: The output directory needs to be created earlier in the armory initialization -so that the logfile can start near the top of run. - -## logging level specification - -As with the standard `logging` module, armory log messages are conditionally emitted -based on their level. Messages sent by armory will be logged at the INFO level -by default. - -But armory.logs also handles messages sent by libraries that we call such as: art, -tensorflow, boto, etc. The armory.logs module has a filter that is applied before -emitting messages and is configured as a dictionary mapping the originating module name -to level such as: - - default_message_filters = { - "": "TRACE" - "armory": "INFO", - "art": "INFO", - "docker": "INFO", - "botocore": "WARNING", - "s3transfer": "INFO", - "urllib3": "INFO", - "absl": False, - "h5py": False, - "avro": False, - } - -which is how the logger is configured at the start. The `""` module is special, and -covers all cases which aren't otherwise specified. So we start with printing all -messages at TRACE and higher (which means all). For messages from armory, art, and -docker, INFO is fine. The botocore and s3transfer modules are crazy chatty so we raise -the threshold for them. I don't know that I've ever heard mention of debug tracing in -absl, h5py, or avro so I've disabled any messages from them. - -I'm not sure these are good defaults, so I am hoping the other armory devs will -give opinions. - -## armory --log-level option - -The command - - armory run --log-level armory:debug --log-level art:debug ... - -overrides the default log-levels for armory and art. Because argparse allows -unique option substrings to be used, this command can be written more briefly -as - - armory run --log debug --log art:debug ... - -as a convenience omitting the `module:` part of the level assumes `armory:`. -The `--debug` option become a deprecated alias for `--log-level armory:debug`. - -The module names are done with a simple text match, so if you see too many messages -like - - 2022-02-24 15:31:19 4s INFO art.estimators.classification.pytorch:get_layers:986 ... - -you can adjust that down with `--log art.estimators:warning` or the hyper-specific -`--log art.estimators.classification:warning`. diff --git a/docs/original/metrics.md b/docs/original/metrics.md deleted file mode 100644 index c17f7882a..000000000 --- a/docs/original/metrics.md +++ /dev/null @@ -1,685 +0,0 @@ -# Measurement Overview - -Armory contains a number of functions to use as metrics as well as flexible measurement instrumentation. - -For measuring and logging standard perturbation (e.g., `Lp` norms) and task metrics (e.g., `categorical_accuracy`) for model inputs and outputs, standard config usage will likely suffice. -See the Metrics section for more information on available metrics. -For custom metrics and measuring intermediate values (e.g., outputs after a certain preprocessing layer), see the Instrumentation section below. - -## Scenario Config Usage - -In scenario configs, described in more detail in [Configuration File](docs/configuration_files.md), standard metrics can be added for measuring tasks and adversarial perturbations. -When running a scenario, these metrics are measured and output in json format in the results file. - -Desired metrics and flags are placed under the key `"metric"` dictionary in the config: -``` -"metric": { - "max_record_size": Integer or null, - "means": [Bool], - "perturbation": List[String] or String or null, - "profiler_type": null or "basic" or "deterministic", - "record_metric_per_sample": [Bool], - "task": List[String] or String or null, - "task_kwargs": List[dict] (Optional) -} -``` -The `perturbation` and `task` fields can be null, a single string, or a list of strings. -The perturbation metrics measure the difference between the benign and adversarial inputs `x`. -The task metrics measure the task performance on the predicted value w.r.t the true value `y`, for both benign and adversarial inputs. -If task metrics take keyword arguments, such as `"iou_threshold"`, these can be (optionally) added a list of kwarg dicts. -The `task_kwargs` list must be the same length as `task`, and metrics without kwargs should have `{}` as a placeholder. -These metrics are called on batches of inputs, but are sample-wise metrics, and so their results are concatenated to form a list over samples. - -When `means` is true, the average value for the given metric is also recorded. -When `record_metric_per_sample` is true, all of the per-sample metrics are recorded. -If neither is true, a `ValueError` is raised, as nothing is recorded. -The `max_record_size` field, if not `null`, will drop individual records sent to the ResultsWriter that are greater than the given value. - To use the default of `2**20` bytes (per record, not per full results output), do not include this field in the config. - -The `profiler_type` field, when not `null`, enables the logging of computational metrics. -If `"basic"`, it logs CPU time for model inference and attacking. -If `"deterministic"`, which runs *very* slowly, also provides verbose CPU statistics at the function call level, like so: -``` - 837 function calls (723 primitive calls) in 0.063 seconds - - Ordered by: cumulative time - - ncalls tottime percall cumtime percall filename:lineno(function) - 1 0.000 0.000 0.063 0.063 /opt/conda/lib/python3.8/site-packages/art/attacks/evasion/fast_gradient.py:207(generate) - 1 0.000 0.000 0.054 0.054 /opt/conda/lib/python3.8/site-packages/art/attacks/evasion/fast_gradient.py:477(_compute) - 1 0.000 0.000 0.053 0.053 /opt/conda/lib/python3.8/site-packages/art/attacks/evasion/fast_gradient.py:383(_compute_perturbation) - 1 0.000 0.000 0.052 0.052 /opt/conda/lib/python3.8/site-packages/art/estimators/classification/keras.py:422(loss_gradient) - 1 0.000 0.000 0.052 0.052 /opt/conda/lib/python3.8/site-packages/keras/backend.py:4238(__call__) - 1 0.000 0.000 0.042 0.042 /opt/conda/lib/python3.8/site-packages/keras/backend.py:4170(_make_callable) - 1 0.000 0.000 0.042 0.042 /opt/conda/lib/python3.8/site-packages/tensorflow/python/client/session.py:1502(_make_callable_from_options) - ... -``` -Profiler information can be found in the results json under `["results"]["compute"]`. -The functionality for these profilers can be found in `armory/metrics/compute.py`. - -### Targeted vs. Untargeted Attacks - -For targeted attacks, each metric will be reported twice for adversarial data: once relative to the ground truth labels and once relative to the target labels. For untargeted attacks, each metric is only reported relative to the ground truth labels. Performance relative to ground truth measures the effectiveness of the defense, indicating the ability of the model to make correct predictions despite the perturbed input. Performance relative to target labels measures the effectiveness of the attack, indicating the ability of the attacker to force the model to make predictions that are not only incorrect, but that align with the attackers chosen output. - -## Metrics - -The `armory.metrics` module contains functionality to measure a variety of metrics: -- `armory.metrics.perturbation` metrics measure adversarial perturbations such as `lp` distance -- `armory.metrics.task` metrics measure task performance such as categorical accuracy -- `armory.metrics.statistical` metrics measure statistical quantities such as KL divergence -- `armory.metrics.poisoning` module contains helper functions to measure fairness statistics relevant to poisoning and filtering scenarios - -We have implemented the metrics in numpy, instead of using framework-specific metrics, to prevent expanding the required set of dependencies. -Please see the relevant submodules in [armory/metrics](../armory/metrics/) for more detailed descriptions. - -### Perturbation Metrics - -Perturbation metrics compare a benign and adversarially perturbed input and return a distance. -Typically, these functions follow the form of `func(x, x_adv)`, where `x` is the benign input and `x_adv` is the perturbed input. - -The set of perturbation metrics provided by armory can also be via batch-wise and element-wise namespaces as follows: -```python -from armory.metrics import perturbation -print(peturbation.batch) -# ['image_circle_patch_diameter', 'l0', 'l1', 'l2', 'linf', 'max_image_circle_patch_diameter', 'max_l0', 'max_l1', 'max_l2', 'max_linf', 'mean_image_circle_patch_diameter', 'mean_l0', 'mean_l1', 'mean_l2', 'mean_linf', 'snr', 'snr_db', 'snr_spectrogram', 'snr_spectrogram_db'] -print(perturbation.element) -# ['image_circle_patch_diameter', 'l0', 'l1', 'l2', 'linf', 'max_image_circle_patch_diameter', 'max_l0', 'max_l1', 'max_l2', 'max_linf', 'mean_image_circle_patch_diameter', 'mean_l0', 'mean_l1', 'mean_l2', 'mean_linf', 'snr', 'snr_db', 'snr_spectrogram', 'snr_spectrogram_db'] -``` -Currently, all perturbation metrics have element-wise and batch-wise versions, though the config assumes that the batch version is intended. -For instance: -```python -perturbation.batch.l1([0, 0, 0], [1, 1, 1]) -# array([1., 1., 1.]) -perturbation.element.l1([0, 0, 0], [1, 1, 1]) -# 3.0 -``` -Metric outputs are numpy arrays or scalars. - -| Name | Namespace | Description | -|-------|-------|-------| -| `linf` | `perturbation.batch.linf` | L-infinity norm | -| `l2` | `perturbation.batch.l2` | L2 norm | -| `l1` | `perturbation.batch.l1` | L1 norm | -| `l0` | `perturbation.batch.l0` | L0 "norm" | -| `snr` | `perturbation.batch.snr` | Signal-to-noise ratio | -| `snr_db` | `perturbation.batch.snr_db` | Signal-to-noise ratio (decibels) | -| `snr_spectrogram` | `perturbation.batch.snr_spectrogram` | Signal-to-noise ratio of spectrogram | -| `snr_spectrogram_db` | `perturbation.batch.snr_spectrogram_db` | Signal-to-noise ratio of spectrogram (decibels) | -| `image_circle_patch_diameter` | `perturbation.batch.image_circle_patch_diameter` | Diameter of smallest circular patch | -| `mean_l(0\|1\|2\|inf)` | `perturbation.batch.mean_l(0\|1\|2\|inf)` | Lp norm averaged over all frames of video | -| `max_l(0\|1\|2\|inf)` | `perturbation.batch.max_l(0\|1\|2\|inf)` | Max of Lp norm over all frames of video | -| `(mean\|max)_image_circle_patch_diameter` | `perturbation.batch.(mean\|max)` | Average or max circle over all frames of video | - -
- -### Task Metrics - -The `metrics.task` module contains metrics for measurement of task performance. -Generally, these functions follow the form of `func(y, y_pred)`, where `y` is the ground truth and `y_pred` is the prediction. -This is true for all of the batchwise and elementwise functions (which behave similarly to the `perturbation` module). -However, not all batchwise functions have elementwise counterparts (e.g., `per_class_accuracy`). - -Those metrics in the `population` namespace take `y_list` and `y_pred_list`, which are indicative of the entire dataset. -They can be called on a subset of the population, but for a correct overall result, it requires the entire set of predictions. - -Some metrics such as total word error rate and mean average precision are effectively aggregations of batchwise metrics, and are in the `aggregate` namespace. -Total word error rate, for instance, requires independently summing the numerators and denominators of the sample word error rates, instead of directly averaging them. -These metrics typically take a list or array of results as their single argument. - -The `apricot`, `carla`, and `dapricot` metrics are effectively the `object_detection` metrics with parameters adapted to those respective scenarios. - -As mentioned, these functions generally compare `y_pred` against `y`, that is, the metric compares a benign or adversarial prediction to the ground truth. It is also possible to use these metrics to compare adversarial predictions against benign predictions. This is not enabled in off-the-shelf Armory code, but can be easily implemented through one small code modification, by simply adding ```self.metrics_logger.add_tasks_wrt_benign_predictions()``` to the ```load_metrics()``` function of the scenario. For example, if you create a new scenario inheriting ```scenario.py```, you can implement ```load_metrics()``` this way: -``` -def load_metrics(self): - super().load_metrics() - self.metrics_logger.add_tasks_wrt_benign_predictions() -``` - -| Name | Namespace | Description | -|-------|-------|-------| -| `categorical_accuracy` | `task.batch.categorical_accuracy` | Categorical Accuracy | -| `top_5_categorical_accuracy` | `task.batch.top_5_categorical_accuracy` | Top-5 Categorical Accuracy | -| `per_class_accuracy` | `task.batch.per_class_accuracy` | Categorical accuracy per class, as a list per class| -| `per_class_mean_accuracy` | `task.batch.per_class_mean_accuracy` | Mean categorical accuray per class | -| `word_error_rate` | `task.batch.word_error_rate` | Word error rate | -| `total_wer` | `task.batch.aggregate.total_wer` | Total word error rate | -| `entailment` | `task.batch.entailment` | Entailment language metric (contradiction, neural, entailment) | -| `total_entailment` | `task.aggregate.total_entailment` | Total entailment | -| `tpr_fpr` | `task.population.tpr_fpr` | Return a dictionary containing TP, FP, TN, FN, TPR, FPR, TNR, FNR, and F1 Score (assuming binary inputs) | -| `video_tracking_mean_iou` | `task.batch.video_tracking_mean_iou` | Mean IOU between ground-truth and predicted boxes, averaged over all frames for a video | -| `video_tracking_mean_success_rate` | `task.batch.video_tracking_mean_success_rate` | Mean success rate averaged over all multiple IOU thresholds and all frames | -| `object_detection_AP_per_class` | `task.population.object_detection_AP_per_class` | Object Detection average precision per class | -| `object_detection_disappearance_rate` | `task.batch.object_detection_disappearance_rate` | Object Detection Disappearance Rate | -| `object_detection_hallucinations_per_image` | `task.batch.object_detection_hallucinations_per_image` | Object Detection Hallucinations Per Image | -| `object_detection_mAP` | `task.population.object_detection_mAP` | Object Detection mean average precision | -| `object_detection_misclassification_rate` | `task.batch.object_detection_misclassification_rate` | Object Detection Misclassification Rate | -| `object_detection_true_positive_rate` | `task.batch.object_detection_true_positive_rate` | Object Detection True Positive Rate | -| `apricot_patch_targeted_AP_per_class` | `task.population.apricot_patch_targeted_AP_per_class` | OD metric applied to apricot scenario | -| `carla_od_AP_per_class` | `task.population.carla_od_AP_per_class` | OD metric applied to carla scenario | -| `carla_od_disappearance_rate` | `task.batch.carla_od_disappearance_rate` | OD metric applied to carla scenario | -| `carla_od_hallucinations_per_image` | `task.batch.carla_od_hallucinations_per_image` | OD metric applied to carla scenario | -| `carla_od_misclassification_rate` | `task.batch.carla_od_misclassification_rate` | OD metric applied to carla scenario | -| `carla_od_true_positive_rate` | `task.batch.carla_od_true_positive_rate` | OD metric applied to carla scenario | -| `dapricot_patch_target_success` | `task.population.dapricot_patch_target_success` | OD metric applied to dapricot scenario | -| `dapricot_patch_targeted_AP_per_class` | `task.population.dapricot_patch_targeted_AP_per_class` | OD metric applied to dapricot scenario | -| `abstains` | `task.batch.abstains` | Takes a batch matrix of inputs and returns 1 for each row that are all 0 (abstention) | -| `identity_unzip` | `task.batch.identity_unzip` | Utility function for mapping from batches to list of samples | -| `identity_zip` | `task.aggregate.identity_zip` | Utility function for mapping from list of samples to single batch | - - -
- -### Statistical Metrics - -The statistical module provide metrics for measurement of statistical and information theoretic quantities. -It also contains helper functions to set up data structures (e.g., contingency tables) for computation with these metrics. - -| Name | Namespace | Description | -|-------|-------|-------| -| `chi2_p_value` | `metrics.statistical.registered.chi2_p_value` | Chi Squared Value | -| `fisher_p_value` | `metrics.statistical.registered.fisher_p_value` | Fisher P-Value | -| `spd` | `metrics.statistical.registered.spd` | Statistical Parity Difference | -| `filter_perplexity_fps_benign` | `metrics.statistical.registered.filter_perplexity_fps_benign` | Perplexity of Filtered Distribution | -| `perplexity` | `metrics.statistical.registered.perplexity` | P-to-Q Perplexity | -| `kl_div` | `metrics.statistical.registered.kl_div` | KL Divergence | -| `cross_entropy` | `metrics.statistical.registered.cross_entropy` | Distributional Cross Entropy | -| `class_bias` | `metrics.statistical.registered.class_bias` | Class Bias | -| `majority_mask` | `metrics.statistical.registered.majority_mask` | Binary mask indicating whether a sample is in the majority of the distribution | -| `class_majority_mask` | `metrics.statistical.registered.class_majority_mask` | Majority mask with majority membership considered on a per-class basis | - -
- -### Poisoning Metrics - -The poisoning scenarios can be configured to measure fairness across classes. -This code is in `armory.metrics.poisoning`, but doesn't constitute typical metric definitions. -Instead, it uses metrics from `statistical` (`chi2_p_value` and `spd`) to measure fairness. -In particular, it uses clustering from the activations of an explanatory model to determine samples that are in the "majority" or "minority" of the distribution, via `class_majority_mask` in `statistical`. -The statistical metrics are then used to compare the fairness across these subpopulations. - -This module mostly contains code to load explanatory models, generate activations, and route the correct data as inputs to the statistical metrics. -For more information, see [poisoning](poisoning.md). -
- -### Custom Metrics - -In order to include custom metrics in configs, there are a few different steps. -NOTE: only perturbation and task metrics are loadable directly from the config at this time. - -In order for your metric to get loaded, it must be retrievable via the following function: -``` -metrics.get(name) -``` -where `name` is the `str` name of your function. Suppose your metric is defined in `my_project/metrics.py` as `hot_dog_ness`. - -Using the custom metric requires providing the full `.`-separated path to the metric function in the config, e.g., `"my_project.metrics.hot_dog_ness"`. -In this case, `metrics.get("my_project.metrics.hot_dog_ness")` will try to import `hot_dog_ness` from `my_project.metrics`. Note the following caveats: -- This case will only work as intended if `hot_dog_ness` is a batchwise function that outputs a list (or array) of results, one per element in the batch -- By default, armory will try to calculate a mean from the output of the custom metric -- Should the name of the custom metric collide with any existing functions supported by armory, armory will throw an error notifying the user of the collision as well as request a name change for the custom metric - -*Optional* An alternative is to use one of the existing decorators in `task` or `perturbation` to register your metric. This is useful for applying a custom metric as a non-batchwise operation and suppressing the mean calculation for outputs with specific formats. -These decorators, their associated namespaces, and the intended APIs of the metric functions they decorate, are: -- `metrics.perturbation.elementwise` - `metrics.perturbation.element` - takes a single pair of `x_i` and `x_adv_i` and returns a single perturbation distance for that element. -- `metrics.perturbation.batchwise` - `metrics.perturbation.batch` - takes a batch of `x` and `x_adv` and returns a list of results, one per data element. -- `metrics.task.elementwise` - `metrics.task.element` - takes a single pair of `y_i` and `y_pred_i` and returns a single result for that element. -- `metrics.task.batchwise` - `metrics.task.batch` - takes a batch of `y` and `y_pred` and returns a list of results, one per data element. -- `metrics.task.populationwise` - `metrics.task.population` - takes lists of `y` and `y_pred` across the entire dataset and computes a single set of metrics, such as mAP. -- `metrics.task.aggregator` - `metrics.task.aggregate` - takes a list of results from a batchwise metric and performs a non-trivial aggregation, such as for calculating total word error rate. - -For instance, if you were adding an accuracy metric for task results, you could do: -``` -from armory import metrics -@metrics.task.elementwise -def my_accuracy_metric(y_i, y_pred_i): - return y_i == np.argmax(y_pred_i) -``` - -Armory performs all built-in metric operations as batches, not as individual elements, so using the `elementwise` decorators will also produce a batchwise version of it that loops through the individual elements and provides a batchwise result. -NOTE: when armory uses `get`, it will get the batchwise version of a metric. - -Once annotated, these will also be `.`-addressable using their respective namespaces. -In the above example, you can get at `my_accuracy_metric` via the `metrics.task.element` namespace: -```python -metrics.task.element.my_accuracy_metric -assert metrics.task.element.my_accuracy_metric is my_accuracy_metric -``` -You can also get the batchwise version of it via: -```python -batchwise_my_accuracy_metric = metrics.task.batch.my_accuracy_metric -``` - -All non-elementwise metrics are registered in the `supported` namespace, which can be looked at via `metrics.supported` or `metrics.common.supported`. - -If the function is decorated with a `populationwise` decorator, then all of the results will be stored in a list until the end of the scenario, then passed to the metric for processing. -We do not support populationwise for perturbation metrics as this would require storing a potentially very large set of input and perturbed input data. - -Another useful decorator currently only supported in `task` is the `aggregator`, which can take intermediate results from a batchwise metric and aggregate them together non-trivially. - -For instance, if have a metric (like word error rate) that returns two values that form a fraction, and you want the aggregate measure to not be the mean over fractions, but the fraction of the sums of the numerator and denominator, that could look like the following: -```python -@metrics.task.elementwise -def fraction(y_i, y_pred_i) -> (int, int): - ... - return numerator / denominator - -@metrics.task.aggregator -# NOTE: the input will be a list (or numpy array) of each element-wise result from the underlying function -def fraction_aggregator(list_of_fraction_tuples) -> (int, int): - total_numerator, total_denominator = 0, 0 - for numerator, denominator in list_of_fraction_tuples: - total_numerator += numerator - total_denominator += denominator - return total_numerator, total_denominator -``` - -In order for the aggregator to be automatically used in armory scenarios, it needs to be registered: -``` -metrics.task.map_to_aggregator("fraction", "fraction_aggregator") -``` -The `map_to_aggregator` maps the `str` name of the batchwise function (`fraction` is here implictly via the elementwise decorator making a batchwise version) to the `str` name of the aggregator function. - -To test, you should be able to do: -``` -aggregator_name = metrics.task.get_aggregator_name("fraction") -assert aggregator_name is not None -aggregator = metrics.get(aggregator_name) -assert aggregator is fraction_aggregator -``` -This sequence of operations is essentially what armory does to resolve the aggregator. - -If an aggregator is not linked to a metric, then it will default to either no aggregator (if `means` is `false` in the config) or to `np.mean` (if `means` is `true` in the config). -If `np.mean` fails, no aggregation result will be recorded, but a warning will be logged. - -#### Log-Based Reporting - -In addition to being output to results json files, results are also logged to the screen at the `"METRIC"` log level, which is between `"PROGRESS"` and `"INFO"`; see [logging](logging.md). -By default, metric results are formatted as follows: `f"{np.mean(result):.3}"`. -If this results in an error (e.g., due to result not being a number or array of numbers), then it defaults to `f"{result}"`. - -In order to provide custom formatting for results logged to screen, you will need to implement and register a formatter for your function. -Following the `fraction` example above, you can do the following: -```python -@metrics.result_formatter("fraction") -def fraction_formatter(result) -> str: - numerator, denominator = result - return f"{numerator} / {denominator}" -``` -The arg provided to the `result_formatter` decorator is the name of the metric you would like to associate with this formatter, which should return a `str`. -If you would like to associate additional metrics with this formatter (e.g., to use it for the aggregation function as well), you can call it directly as follows: -```python -metrics.result_formatter("fraction_aggregator")(fraction_formatter) -``` - -#### Class-based Metrics - -The previous description assumes that the metric is a callable function. -It is sometimes necessary or helpful for a metric to be contained in a class. -When loading, if the target returned by `metrics.get` is a class, it will attempt to instantiate the class (without args or kwargs), and use the instantiated callable object as the metric function. -Otherwise, it should operate just like a simple function metric. - -## Instrumentation - -The `armory.instrument` module implements functionality to flexibly capture values for measurement. - -The primary mechanisms are largely based off of the logging paradigm of loggers and handlers, though with significant differences on the handling side. - -- Probe - object to capture data and publish them for measurement. -- Meter - object to measure a single metric with given captured data and output records -- Writer - object to take meter output records and send them standard outputs (files, loggers, results dictionaries, etc.) -- Hub - object to route captured probe data to meter inputs and route meter outputs to writers -- There is typically only a single hub, where there can be numerous of the other types of objects. - -### Quick Start - -In order to capture and measure values, you need a Probe and a Meter connected to the hub, at a minimum: -```python -from armory.instrument import get_probe, Meter, get_hub, PrintWriter -hub = get_hub() # get global measurement hub -probe = get_probe("probe_name") # get probe connected to global hub -meter = Meter("my_meter", lambda a,b: a+b, "probe_name.a", "probe_name.b") # construct meter that measures the sum of a and b -hub.connect_meter(meter) # connect meter to global hub - -# optionally, add a writer -writer = PrintWriter() -hub.connect_writer(writer, default=True) # default sets all meters to use this writer - -# Now, measure -probe.update(a=2, b=5) # should also print to screen if PrintWriter is connected -probe.update(a=3) -probe.update(b=8) # now it should print again -results = meter.results() -assert results == [7, 11] -``` - -Since these all use a global Hub object, it doesn't matter which python files they are instantatied in. -Probe should be instantiated in the file or class you are trying to measure. -Meters and writers can be instantiated in your initial setup (please refer to [User Initialization](./scenarios.md#user-initialization) for more details about using the `user_init` block), and can be connected before probes are constructed. - -#### Direct Recording - -To capture one-off values or values that do not require metric measurement, you can push a record to the hub directly using its `record` method: -``` -hub = get_hub() -name = "my_record" -result = 17 -hub.record(name, result) -``` -This will push a record to all default writers (including the `ResultsWriter` in standard scenarios) with that information. -To send it to an additional writer or writers, you can supply them with the `writers` kwargs, which can take a single writer or an iterable of writers. -To not send it to the default writers, set the `use_default_writers` kwarg to `False`. -For instance: -``` -my_writer = PrintWriter() -hub.record(name, result, writers=my_writer, use_default_writers=False) -``` -If `writers` is empty or None and `use_default_writers` is False, no record will be sent and a warning will be logged. - -### Probes - -To get a new Probe (connected to the default Hub): -```python -# Module imports section -from armory.instrument import get_probe -probe = get_probe(name) -``` -The arg `name` can be any `str` that is a valid python identifier, or can be blank, which defaults to the empty string `""`. -Similarly to `logging.getLogger`, this provides a namespace to place variables, and inputs like `__name__` can also be used. -Calls to `get_probe` using the same name will return the same Probe object. -The recommended approach is to set a probe at the top of the file of interest and use it for all captures in that file. - -To capture values in-line, use `update`: -```python -# ... -# In the code -probe.update(name=value) -``` - -This will publish the given value(s) to the given name(s) (also called probe variables) in the probe namespace of the connected Hub. -To be more concrete: -```python -probe = get_probe("my.probe_name") -probe.update(arbitrary_variable_name=15) -``` -will push the value 15 to `"my.probe_name.arbitrary_variable_name"`. -These names will be used when instantiating `Meter` objects. - -However, this will fall on the floor (`del`, effectively) unless a meter is constructed and connected to the Hub to record values via `connect_meter`. -See the Quick Start section above or the Meters section below for more details. -This is analogous to having a `logging.Logger` without an appropriate `logging.Handler`. - -Multiple variables can be updated simultaneously with a single function call (utilizing all kwargs given): -```python -probe.update(a=x, b=y, c=z) -``` - -Sometimes it is helpful to perform preprocessing on the variables before publishing. -For instance, if the variable `y` was a pytorch tensor, it might be helpful to map to numpy via `y.detach().cpu().numpy()`. -However, it would be a waste of computation of nothing was set up to measure that value. -Therefore, probes leverage `args` to perform preprocessing on the input only when meters are connected. -For instance, -```python -probe.update(lambda x: x.detach().cpu().numpy(), my_var=y) -``` -Or, less succinctly, -```python -probe.update(lambda x: x.detach(), lambda x: x.cpu(), lambda x: x.numpy(), my_var=y) -``` -More generally, -```python -probe.update(func1, func2, func3, my_var=y) -``` -will publish the value `func3(func2(func1(y)))`. - -#### Interactive Testing - -An easy way to test probe outputs is to set the probe to a `MockSink` interface. -This can be done as follows: -```python -from armory.instrument import get_probe, MockSink -probe = get_probe("my_name") -probe.set_sink(MockSink()) -probe.update(variable_name=17) -# update probe variable my_name.variable_name to 17 -``` -This will print all probe updates to the screen. - -### Default Scenario Probe Values - -The standard scenarios provide probe updates for the following variables: -- `i` - the current batch -- `x` - current batch of inputs -- `y` - current batch of ground truth labels -- `y_pred` - prediction of model on `x` -- `x_adv` - inputs perturbed by the current attack -- `y_pred_adv` - prediction of model on `x_adv` -- `y_target` (conditional) - target labels for attack, if attack is targeted - -The standard probe used in scenarios is named `"scenario"`, so to access these, prepend the variable with `"scenario."`. -For example, the variable `x` set in the scenario can be referenced as `"scenario.x"`. - -### Meter - -A Meter is used to measure values output by probes. -It is essentially a wrapper around the functions of `armory.utils.metrics`, though it can employ any callable object. -You will need to construct a meter, connect it to a hub, and (optionally) add a writer. - -#### Meter Construction - -To instantiate a Meter: -```python -from armory.instrument import Meter -meter = Meter( - name, - metric, - *metric_arg_names, - metric_kwargs=None, - auto_measure=True, - final=None, - final_name=None, - final_kwargs=None, - record_final_only=False, -) -""" -A meter measures a function over specified input probe_variables for each update - If final is not None, it also measures a function over those measurements - Records are pushed to Writers for output - -name - str name of meter, used when writing records -metric - callable function -metric_arg_names - str names of probe_variables corresponding to args passed into the metric function - Meter(..., "model.x_post[benign]", "model.x_adv_post", ...) - Follows the pattern of `probe_name.probe_variable[stage]` (stage is optional) -metric_kwargs - kwargs for the metric function that are constant across measurements - -auto_measure - whether to measure when all of the variables have ben set - if False, 'measure()' must be called externally - -final - metric function that takes in the list of results as input (e.g., np.mean) -final_name - if final is not None, this is the name associated with the record - if not specified, it defaults to f'{final}_{name}' -final_kwargs - kwargs for the final function that are constant across measurements -record_final_only - if True, do not record the standard metric, only final - if record_final_only is True and final is None, no records are emitted -""" -``` - -For example, if you have a metric `diff`, -```python -def diff(a, b): - return a - b -``` -and you want to use it to measure the difference between `w` and `z` output from Probe `"my_probe"`, then you could do: -```python -meter = Meter( - "my_meter_name", - diff, - "my_probe.w", - "my_probe.z", -) -``` -This will effectively call `diff(value["my_probe.w"], value["my_probe.z"])` once for each time both of those values are set. - -If you wanted to take the average of diff over all the samples and only record that value, you would need to set final. -```python -meter = Meter( - "name not recorded because record_final_only is True", - diff, - "my_probe.w", - "my_probe.z", - final=np.mean, - final_name="mean_meter", # actual recorded name - final_kwargs=None, - record_final_only=True, -) -``` - -A more succinct way of doing this, which also handles the case when only batches of `w` and `z` are supplied to the meter, is to use `GlobalMeter`: -```python -meter = GlobalMeter( - "mean_meter", # actual recorded name - np.mean, - "my_probe.w", - "my_probe.z", - final_kwargs=None, -) -The `GlobalMeter` assumes that inputs are batches, so if multiple batches are passed, they will be concatenated along the first axis. -Note that if multiple batches are passed, all variables from a specific batch must be passed to the meter before moving to the next batch, in order to avoid dropping. - -The `metric_kwargs` and `final_kwargs` are a set of kwargs that are passed to each call of the corresponding function, but are assumed to be constant. -For example, this could be the `p` parameter in a generic `l_p` norm: -```python -def lp(x, x_adv, p=2): - return np.linalg.norm(x-x_adv, ord=p, axis=1) - -meter = Meter( - "lp_perturbation", - lp, - "scenario.x", - "scenario.x_adv", - metric_kwargs={"p": 4}, -) -``` - -#### Connecting Meter to Hub and Receiving Probe Updates - -A constructed meter needs to be connected to a hub to receive `probe_variable` updates: -```python -from armory.instrument import get_hub -hub = get_hub() # use global hub -hub.connect_meter(meter) -``` - -Updates are propagated to meters via the hub based on a simple filtering process. -If a probe named `probe_name` is updating a value `my_value` to 42, the call looks like this: -```python -get_probe("probe_name").update(my_value=42) -``` -The hub then looks for a corresponding name from the lists of `metric_arg_names` from connected meters. -If the name is found, then the hub will call `set` on each of those meters, updating that argument value: -```python -meter.set("probe_name.my_value", 42, batch) -``` -The `batch` arg is mainly used to track which iteration the meter is on, and is set automatically in scenarios. - -Once all of the args have been set for a meter, it will call `self.measure()` if `auto_measure=True` (the default). -If `auto_measure=False`, then the user will need to explicitly call `meter.measure()` - -NOTE: if `meter_arg_names` are misspelled, the meter will not measure anything. -This will log a warning if nothing has been called when meter.finalize() is called (typically via `hub.close()`), such as: -```python -Meter 'my_meter_name' was never measured. The following args were never set: ['probe_name.my_value'] -``` - -#### Retrieving Results and Records - -After measurement, the results are saved in a local list on the Meter and send records to any connected writers. -Similarly, after finalize is called, the final metric (if it is not `None`) will be applied to the results and saved in a local list, with a record sent to connected writers. - -To retrieve a list of the values measured thus far, call `meter.results()`. -To retrieve the value computed by the final metric, call `meter.final_result()`. -If `measure` and `finalize` have not been called, respectively, then these will instead return `[]` and `None`. - -Records are sent as 3-tuples to connected writers: -```python -(name, batch, result) -``` -where `name` is the name given to the Meter, batch is the number set by the hub, and result is the result from calling the metric. -Final records are also 3-tuples: -```python -(final_name, None, final_result) -``` -Note that the results stored by the meter are not the record tuples, but simply the raw results. - -#### Connecting Writers - -Armory scenarios will set up a default `ResultsWriter` that will take all connected meter records and write them to the output results json. -If additional outputs are desired, other Writer objects can be instantiated and connected to meters via the hub. - -For instance, attaching a simple writer that prints all records to stdout: -```python -hub.connect_writer(PrintWriter(), default=True) -``` - -However, this can be quite verbose, so if you just want to add it to a particular meter, you can do this: -```python -hub.connect_meter(meter) # meter must be connected before connecting a writer to it -hub.connect_writer(PrintWriter(), meters=[meter]) -``` - -The are a number of different standard Writer objects: -- `Writer` - base class other writers are derived from -- `NullWriter` - writer that does nothing (writes to null) -- `LogWriter` - writer that writes to armory log in the given log level. Example: `LogWriter("WARNING")` -- `FileWriter` - writer that writes each record as a json-encoded line in the target file. Example: `FileWriter("records.txt")` -- `ResultsWriter` - writer that collates the records and outputs them as a dictionary. Used by scenarios as default. - -To create a new Writer, simply subclass Writer and override the `_write` method (and optionally the `_close` method). - -#### Stages and Update Filters - -Conditional code may want to take advantage of being able to measure only at certain points in time or compare different stages of a scenario. - -The `Hub` class contains context information that can be leveraged to filter out probe updates. -These are set by the `hub.set_context` method, and are automatically set by scenarios. -Currently, context contains the keys `batch` (number) and `stage`, which are respectively set to `int` and `str` values. -Future updates may extend the use of context information for more advanced filtering or measurement. - -The batch number is incremented once per batch, is typically set to -1 prior to the first batch, and is primarily used internally by Meters to synchronize their measurements across stages. -The stage is intented primarily for filtering, starts with an empty string for a value, and is updated with logical parts of the scenario. -The primarily used scenario contexts (at present) for evasion attacks are: -- "next" - data iteration (get `x`, `y`, `i`, etc.) -- "benign" - model prediction on `x` -- "attack" - attack to generate `x_adv` from `x` -- "adversarial" - model prediction on `x_adv` -- "finished" - indicates that all benign and adversarial batches have been evaluated -Scenario contexts for poisoning scenarios are varied - see the scenarios for specifics. - -We do not recommend directly setting context while running a scenario, or it will interfere with the standard meters. -However, these will likely need to be set when running a custom scenario and overriding standard methods like `next`, `run_benign`, and `run_attack`. - -Probe updates can be filtered by meters by using a single bracketed string in the args list. -For instance, `"probe_name.probe_variable[adversarial]"` will only measure the value from `"probe_name.probe_variable"` when `stage = "adversarial"`. - -This can be helpful when you want to measure something internal to a model but only during certain stages. -For instance, if you have a two stage model that applies preprocessing followed by estimation, and you want to measure the value after preprocessing: -```python -probe = get_probe("my_model") - -def forward(self, x): - x_proc = preprocessing(x) - probe.update(x_after_preprocess=x_proc) - y_pred = estimation(x_proc) - return y_pred -``` -You may want to compare the "linf" distance of `x_proc` in the benign case to `x_proc` for the corresponding adversarial case. -However, the model does not know the present context (whether it is being attacked or in otherwise), so measuring `"my_model.x_after_preprocess"` will get all of the forward passes caused by PGD. -In contrast, the following will directly measure the desired values: -```python -meter = Meter( - "linf of x_proc benign vs adversarial", - metrics.linf, - "my_model.x_after_preprocess[benign]", - "my_model.x_after_preprocess[adversarial]", -) -``` diff --git a/docs/original/no_docker_mode.md b/docs/original/no_docker_mode.md deleted file mode 100644 index e99308fea..000000000 --- a/docs/original/no_docker_mode.md +++ /dev/null @@ -1,100 +0,0 @@ -Armory No-Docker Mode -======================= -In order to run armory in `--no-docker` mode, you will need a properly -setup environment. Generally folks have used conda in the past, however this -document only requires a python (>=3.7) environment to get going. - -First you will need to clone the armory repo (or if you plan to be a developer, -see [Contributing to Armory](./contributing.md) to clone a fork of the repo). -For the following, the repo directory will be referred to as `[armory-repo]`. - -Virtual environment setup for conda is fairly straight forward: -```bash -wget --quiet https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh -O ~/miniconda.sh -/bin/bash ~/miniconda.sh -b -p /opt/conda -conda install -c conda-forge -n base mamba \ -mamba env update -f environment.yml -n base --prune -mamba clean --all -``` - -Alternatively, if your system already has the necessary libraries installed, a virtual -environment can be created with the following commands: -```bash -cd [armory-repo] -python38 -m venv venv38 -source venv38/bin/activate -``` - -Check out the [Dockerfiles](../docker) for more information on environment setup. - -Once this is complete, and you have ensured you are in the `[armory-repo]` directory, -you can setup the environment with the following: -```bash -pip install --upgrade pip==22.0.3 -pip install -e .[engine,datasets,math,pytorch,deepspeech,tensorflow] -``` - -If you are using the `deepspeech` scenarios, you will also need to -install the `hydra-lightning` configs with: - - pip install git+https://github.com/romesco/hydra-lightning/#subdirectory=hydra-configs-pytorch-lightning - -as described [in that package's README](https://github.com/romesco/hydra-lightning#readme). -This is necessary because there is no proper release of that package (nor does one -appear likely). - -Once this completes, you should run `armory configure` (If you haven't already done this -previously) to setup the armory configuration -(e.g. dataset download directory, output directory, etc.). - -With this complete, you now can run armory using `armory run -h`. If you would -like to test the installation / environment, we have provided some base tests that -can be executed using: -```bash -pytest -s ./tests/unit/test_no_docker.py -``` - -This runs a series of configs in a variety of ways to ensure that -the environment is operating as expected. - -NOTE: If you run into issues running pytest (e.g. sometimes your `$PATH` is configured -to point to a global pytest that is outside your virtualenv) directly, you can use the -alternative approach (make sure your virtualenv is active): -```bash -python -m pytest -s ./tests/unit/test_no_docker.py -``` - -If you would like to run the example interactively you -enter a python session in the virtualenv and type: -```python -from armory.scenarios.main import get as get_scenario -from armory import paths -from pathlib import Path - -# Armory needs to have the paths set correctly -paths.set_mode("host") - -config = Path("scenario_configs/no_docker/cifar_short.json") -s = get_scenario(config).load() -s.evaluate() -``` - -## Run baseline CIFAR-10 config - -Now to see if everything is operating correctly you can run the config file -of your choice. The two provided below are truncated in their execution to -demonstrate functionality of armory and, therefore, will not produce accurate -results. For more accurate results (and potentially longer running times) please -see [Armory Baseline Scenario Configs](../scenario_configs/) - -#### [CIFAR-10 Short](../scenario_configs/no_docker/cifar_short.json). - -```bash -armory run ./scenario_configs/no_docker/cifar_short.json --no-docker -``` - -#### [CARLA Short](../scenario_configs/no_docker/carla_short.json). - -```bash -armory run ./scenario_configs/no_docker/carla_short.json --no-docker -``` diff --git a/docs/original/poisoning.md b/docs/original/poisoning.md deleted file mode 100644 index 3a8c234d8..000000000 --- a/docs/original/poisoning.md +++ /dev/null @@ -1,203 +0,0 @@ -# Poisoning - -Updated October 2022 - -Armory supports a handful of specific poisoning threat models and attacks. This document will first describe these, providing enough background for newcomers to get up to speed on what these attacks do. Then, the peculiarities of the poisoning configs will be addressed, including lots of helpful information about Witches' Brew. Finally, we will describe the poisoning-specific metrics. - - -## Threat Models - -There are currently four threat models handled by Armory: dirty-label backdoor, clean-label backdoor, Witches' Brew (clean-label gradient matching), and Sleeper Agent. In a backdoor attack, an adversary adds a small trigger, or backdoor, to a small portion of the train set in order to gain control of the the model at test time. -The trigger is usually a small (but not imperceptible) image superposed on the data, and the adversary's goal is to force the model to misclassify test images that have the trigger applied. Armory includes several trigger images under `utils/triggers/`. - - -In poisoning attacks, the term _source class_ refers to the label of the image(s) that the adversary hopes to misclassify. In the case of a targeted attack, the _target class_ is the desired misclassification label. Neither of these terms describes which class gets poisoned; that depends on the threat model. All of Armory's poisoning scenarios perform targeted attacks. For simplicity, most Armory scenarios assume a single source class (all images to misclassify are from the same class) and a single target class (all misclassifications are aiming for the same label). The exception is Witches' Brew, which accepts images from arbitrary source classes that can all have distinct targets. - - -### Dirty-label backdoor - -In a [Dirty-label Backdoor (DLBD) Attack](https://arxiv.org/abs/1708.06733), training images are chosen from the source class, have a trigger applied to them, and then have their labels flipped to the target class. The model is then trained on this modified data. The adversary's goal is that test images from the source class will be classified as `target` when the trigger is applied at test time. - -#### Audio - -The DLBD attack for audio is similar to that of video. The difference is that instead of the trigger being an image that is placed over the existing image, the trigger is a short audio clip that is mixed with the existing audio. Example configs for speech are [here](../scenario_configs/eval6/poisoning) -Current triggers include a whistle and clapping. - -### Clean-label backdoor - -In a [Clean-label Backdoor (CLBD) Attack](https://people.csail.mit.edu/madry/lab/cleanlabel.pdf), the triggers are applied to target-class images during training. The poisoned samples also undergo some imperceptible gradient-based modifications to weaken the natural features, thus strengthening the association of the trigger with the target class label. -At test time, the adversary applies the trigger to source-class images in order to get them to misclassify as `target`. - - - -### Witches' brew - -[Witches' Brew](https://arxiv.org/abs/2009.02276) is a clean-label attack but there is no backdoor or trigger involved. The adversary selects individual `source` images from the test set; these are the images that the adversary wants to misclassify as `target` and are called _triggers_, not to be confused with the backdoor trigger described before. The attack uses a gradient-matching algorithm to modify a portion of the train-set target class, such that the unmodified test-set triggers will be misclassified. - -Because witches' brew is so different a threat model from the backdoor attacks that `poison.py` was initially built for, it has its own scenario. - - -### Sleeper Agent - -[Sleeper Agent](https://arxiv.org/abs/2106.08970) is a clean-label attack that applies $l_\infty$ bounded perturbations to a set of training images to embed a hidden trigger into the model that can be applied at inference time. -This threat model does not assume access to the target architecture, but instead trains a surrogate model to produce the perturbations. -This approach uses gradient alignment to optimize the perturbations for the trigger. - - -## Configuration files - -The config format for poisoning is currently complex and disorganized. The metrics section is ignored. -Parameters for attacks and defenses may be scattered between the attack, defense, and adhoc sections. -There are fields that seem to be copied and pasted from config to config with no consideration of whether they are needed. - -A key thing to be aware of is that for DLBD attacks, the amount of data to poison is set under `adhoc/fraction_poisoned` and refers to the fraction of the source class to poison, not the whole dataset. However, for CLBD attacks, this parameter is set under `attack/kwargs/pp_poison`. For witches' brew, it is again set under `adhoc/fraction_poisoned`, but this time it refers to the percentage of the entire dataset. In the latter case, since only the target class is poisoned, `fraction_poisoned` will be clipped to the actual size of the target class. If there are multiple triggers with different target classes, the amount of poison will be split between target classes. - -The `adhoc` section of the config is where most of the configuration action happens for poisoning attacks. Most of the fields under `adhoc` would belong better in other sections. A deprecation of the `adhoc` section is on the horizon, but in the meantime, here's a brief description. - -The `adhoc` section is where `source_class`, `target_class`, and `train_epochs` are set. The fields `compute_fairness_metrics` and `explanatory_model` go together, because the explanatory model is used to compute the fairness metrics, as described in the next section. If the defense is a filtering defense and is separate from the model, it can be turned off with `use_poison_filtering_defense:false`. Dataset poisoning can be turned off by setting `poison_dataset:false`; this has been the de facto approach to testing 0% poison, because ART throws an error in some cases when fraction poisoned is set to 0. A final flag to note is `fit_defense_classifier_outside_defense`; this pertains to filters or other defenses that are external to the model and defaults to `true`. If the defense does not require a trained model to operate, you can save time by setting this to `false`, because even if no defense classifier is provided, it will automatically train a copy of the model under evaluation . - -The remaining sections are fairly straightforward. The `attack` section carries the parameters for the attack (those not specified under `adhoc`, that is), including the size, position, and blend of backdoor triggers if applicable. The `defense` section for the _perfect filter_ baseline defense merits some explanation. Because a perfect filter requires knowledge of which data were poisoned, and this information is not available to defenses, the perfect filter is implemented directly in scenario code. However, Armory config validation currently requires a value for `module` and `name` under the `defense` section: the baseline configs set these to `"null"` (the string) although any string will work because the scenario ignores those values if `perfect_filter:true` is present in `defense/kwargs`. - -### Sleeper Agent parameters - -The configuration parameters for sleeper agent largely follows from the [ART implementation](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/poisoning/sleeper_agent_attack.py). -A couple of key differences include the `patch` kwarg being a path to a file instead of an array, with `patch_size` being used to resize the image to the desired size, and `k_trigger` being the number of train images to select for generating the trigger. -Other differences are minor word changes, and can be found [here](https://github.com/twosixlabs/armory/blob/master/armory/scenarios/poisoning_sleeper_agent.py#L101-L113). - - -### Witches' Brew trigger specification - -Witches' Brew requires a `source_class`, `target_class`, and `trigger_index`. The field `target_class` is required, but either of the other two may be left `null`. If `trigger_index` is `null`, triggers will be chosen randomly from the source class. If `source_class` is `null`, it will be inferred from the class labels of images at the provided trigger index. - -Witches' Brew seeks to misclassify individual images; each has to be specified explicitly. If multiple triggers are desired, there are several equivalent ways to accomplish this. Some examples will illustrate. Suppose you want three trigger images from class 1, each with a target class of 0. The following configurations are equivalent: - -``` -source_class: 1 -target_class: 0 -trigger_index: [null, null, null] - -source_class: [1,1,1] -target_class: 0 -trigger_index: null - -source_class: 1 -target_class: [0,0,0] -trigger_index: null - -source_class: [1,1,1] -target_class: [0,0,0] -trigger_index: null - -source_class: [1,1,1] -target_class: [0,0,0] -trigger_index: [null, null, null] -``` -Similarly, you can request triggers from different source classes by doing something like this: -``` -source_class: [1,2,3] -target_class: 0 -trigger_index: null -``` -(selects triggers randomly from classes 1, 2, and 3, each with a target of 0). - -Or this: -``` -source_class: [null, null, null] -target_class: [4,5,6] -trigger_index: [10,20,30] -``` -(Uses images 10, 20, and 30 as triggers, whatever their source label, with targets of 4, 5, and 6 respectively. Note that source and target class may not be the same.) - - -### Witches' Brew dataset saving and loading - -Because generating poisoned data takes so much longer for Witches' Brew than for the backdoor attacks, Armory provides a means to save and load a poisoned dataset. A filepath may be provided in the config under `attack/kwargs/data_filepath`. If this path does not exist, Armory will generate the dataset and save it to that path. If the path does exist, Armory will load it and check that it was generated consistent with what the current config is requesting, in terms of source, target, perturbation bound, and so forth. If there are any discrepancies, a helpful error is raised. If you are loading a pre-generated dataset, `source_class`, `target_class`, and `trigger_index` may all be null. If you want to re-generate a poisoned dataset that already exists, you can delete the old one or rename it. Alternatively, you may set `attack/kwargs/overwrite_presaved_data:true`, but use caution: if you forget to reset it to `false`, or pass the config to someone else, it can take a lot of time to re-generate the poison. - - -## Metrics - -The four primary poisoning metrics are: -- `accuracy_on_benign_test_data_all_classes` -- `accuracy_on_benign_test_data_source_class` -- `accuracy_on_poisoned_test_data_all_classes` -- `attack_success_rate` - -These are computed after the model is trained on a poisoned dataset. First, all of the test data is evaluated with no poison. This gives us the first two metrics. Next, data from the source class is poisoned and evaluated again. The third metric, `accuracy_on_poisoned_test_data_all_classes`, is the total classification accuracy when the source class is poisoned. The fourth metric, `attack_success_rate`, only measures the percentage of source-class examples that are misclassified as `target`. In a well-executed attack, all these metrics will have high values: the first indicating that we have an effective, well-trained model; -the second confirming that the model is accurate on the source class; the third showing that total accuracy does not decrease substantially when one class is poisoned, and the fourth demonstrating that we can induce targeted misclassification in the source class. - - -If the defense under evaluation is a filtering defense, Armory will report traditional statistics on the filter, such as true and false positives and F1 score. -We also log the number of samples poisoned, and the number and percentage of samples filtered out of each class. All metrics are computed automatically without regard to the `metric` field of the configuration file. - -### Fairness Metrics - -The GARD poisoning group has come up with two new per-class metrics to assess the bias of models within subpopulations of each class. -In the following explanation, these will be referred to as Filter Bias and Model Bias. - -Both of these metrics are measured over sub-class clusters of data. -To obtain these clusters, a pre-trained _explanatory model_ (distinct from the model under evaluation) produces activations for all the data, and each class is then partitioned into two subclasses based on a _silhouette score_ computed on the activations. This clustering method is intended to reflect one possible concept of majority/minority, by grouping data together whose silhouette score is within a range deemed to be "normal", while all the other data are considered as outliers in some respect. - -Once we have this partitioning of each class, we can compute some interesting metrics. The primary test is Statistical Parity Difference (SPD), which measures the difference in the probability of some event between two sets. -For two mutually exclusive sets $A$ and $B$, let $X$ be the event we care about, and $\mathrm{P}_A(X)$ is the probability of $X$ occuring over $A$. Then $SPD_X(A,B) := \mathrm{P}_A(X) - \mathrm{P}_B(X).$ Values of SPD range from -1 to 1, with values closer to 0 indicating less bias. - -For the Model Bias metric, the event of interest is correct classification. Let $C_1$ and $C_2$ be a partition of a single class $C$ (i.e. $C = C_1 \cup C_2$ but $C_1 \cap C_2 = \emptyset$ ), and let $m(C)$ measure the number of elements of $C$ classified correctly by the model. -Then the Model Bias metric computes - -$SPD_m(C) = \frac{m(C_1)}{|C_1|} - \frac{m(C_2)}{|C_2|}$. - - -The Filter Bias metric is very similar, only the event of interest is removal from the dataset by the filter. Let $f(C)$ be the number of elements of $C$ that are removed by the filter. Then the Filter Bias metric computes - -$SPD_f(C) = \frac{f(C_1)}{|C_1|} - \frac{f(C_2)}{|C_2|}$. - - -In addition to SPD, we can compute any number of interesting statistics on the contingency tables formed by the subclass populations and the binary attributes of model correctness and filter removal. Currently, Armory also reports the $\chi^2$ $p$-value of the contingency table for each class. The $\chi^2$ test measures the likeliness of the contingency table if we expected no difference in model or filter behavior on different subpopulations of data. Values range from 0 to 1, with a _higher_ value indicating _less_ bias. - - - -### Filter Perplexity - -Another filter metric we currently report is _perplexity_. While the previous fairness metrics assess bias within individual classes, perplexity gives a bigger picture of filter bias between all classes. -The intuition behind this metric is that an unbiased filter should behave the same on all unpoisoned data, so that if there are false positives, they should not overwhelmingly be from a single class, but be spread evenly among all classes. -Perplexity characterizes the difference between two distributions with values from 0 to 1, -with a higher value indicating that the two distributions are more similar (it is equal to 1 if the distributions are identical). We compare the class distribution of false positives with the class distribution of clean data. - - -Let $p(C_i)$ be the fraction of all false positives with class label $i$, and let $q(C_i)$ be the fraction of all unpoisoned datapoints with class label $i$. Note that both $p$ and $q$ include the (unpoisoned part of the) poisoned class, as it is possible to be biased toward that class just as to any other. Perplexity is defined as the exponential of the KL divergence between the two distributions, -$e^{\mathrm{KL}(p||q)}$, where - -$\mathrm{KL}(p||q) = \sum_i{p(C_i)\log}{\frac{p(C_i)}{q(C_i)}}$. - - - -### Witches' Brew - -Because test-time data is not poisoned for the witches' brew attack, it doesn't make sense to use the four primary metrics described above. Instead, we have these three: -- `accuracy_on_trigger_images` -- `accuracy_on_non_trigger_images` -- `attack_success_rate` - -`attack_success_rate` is the percentage of trigger images which were classified as their respective target classes, while `accuracy_on_trigger_images` is the percentage of trigger images that were classified as their natural labels (source classes). Similarly, `accuracy_on_non_trigger_images` is the classification accuracy on non-trigger images. - -The fairness and filter metrics remain the same. - -## Avoiding Out-Of-Memory (OOM) Errors - -The poisoning scenarios typically work with very large in-memory numpy arrays. -This can result in OOM errors in certain cases. - -One place where this can happen is when calling `fit` on the model. -If the model is a TensorFlowV2Classifier (ART), then the `fit` method will try to convert the entire numpy array to a tf tensor (not batched), which can exceed GPU memory for smaller cards, especially for the audio poisoning scenario. -If this is the case, set the scenario kwarg `fit_generator` to `true` in the config: -``` - ... - "scenario": { - "kwargs": { - "fit_generator": true - }, - ... -``` -This will wrap the numpy array in a generator, and send batched inputs into the ART model's `fit_generator` method. -This is less efficient and trains slower than the other method, which is why is not default, but will avoid the OOM error in this case. - -When `fit_generator` is set to `true`, and there is an explanatory model present, it will get activations from the dataset in a batched manner, which avoids a similar OOM error. diff --git a/docs/original/scenarios.md b/docs/original/scenarios.md deleted file mode 100644 index 156db7a51..000000000 --- a/docs/original/scenarios.md +++ /dev/null @@ -1,523 +0,0 @@ -# Scenarios -Armory is intended to evaluate threat-model scenarios. -Baseline evaluation scenarios are described below. -Additionally, we've provided some academic standard scenarios. - - -## Configuration Files -Scenario configuration files are found in the `scenario_configs` directory [here](scenario_configs). -The most recent config files are found in the `eval6` subfolder and older configs are found in the `eval5` and `eval1-4` subfolders. -There are also symlinks to representative configs found in the base of the `scenario_configs` directory. - - -## Base Scenario Class -All scenarios inherit from the [Scenario](https://github.com/twosixlabs/armory/blob/master/armory/scenarios/scenario.py) class. -This class parses an armory configuration file and calls its `evaluate` method to perform all of the computation for a given threat-models robustness to attack. -All `evaluate` methods save a dictionary of recorded metrics which are saved into the armory `output_dir` upon completion. -Scenarios are implemented as subclasses of `Scenario`, and typically given their own file in the [Scenarios Directory](https://github.com/twosixlabs/armory/blob/master/armory/scenarios/). - -Of particular note is the [Poison](https://github.com/twosixlabs/armory/blob/master/armory/scenarios/poison.py) class, from which all poisoning scenarios are subclassed. -More information on poisoning scenarios is documented [here](poisoning.md). - -### User Initialization - -When adding custom metrics or instrumentation meters to a scenario, it may be necessary to initialize or perform user-specific operations before loading. -This can also be helpful for other goals, such as fine-grained control over random initializations, instantiating external integrations (e.g., TensorBoard), or setting things like environment variables. -For this purpose, there is a `user_init` method that is called at the beginning of `load` (but after scenario initialization). -In poisoning, this occurs right after random seed setting in `load` (to enable the user to easily override random initialization). - -This uses the underlying scenario config field of the same name, `user_init`. -See [configuration](configuration_files.md) for the json specification. -An example config would be as follows: -```json - ... - "user_init": { - "module": "import.path.to.my_module", - "name": "my_init_function", - "kwargs": { - "case": 1, - "print_stuff": false - } - } -} -``` -Which would essentially do the following before loading anything else in the scenario: -```python -import import.path.to.my_module as my_module -my_module.my_init_function(case=1, print_stuff=False) -``` -If `name` were `""` or `None`, then it would only do the import: -```python -import import.path.to.my_module -``` - -This could be helpful for a variety of things, such as registering `metrics` prior to loading or setting up custom meters. -For instance: -```python -def my_init_function(): - from armory.instrument import Meter, get_hub - from armory import metrics - m = Meter( - "chi_squared_test", - metrics.get("chi2_p_value"), - "my_model.contingency_table", - ) - get_hub().connect_meter(m) -``` -Would enable measurement of a contingency table produced by your model. -This would require adding probe points in your model code to connect it (which doesn't need to be in the init block), e.g.: -```python -from armory.instrument import get_probe -probe = get_probe("my_model") - -class MyModel(torch.nn.Module): - ... - def forward(x): - ... - table = np.array([[2, 3], [4, 6]]) - probe.update(contingency_table=table) - ... -``` - - -## Baseline Scenarios -Currently the following Scenarios are available within the armory package. -Some scenario files are tied to a specific attack, while others are customized for a given dataset. Several are more general-purpose. -Along with each scenario description, we provide a link to a page with baseline results for applicable datasets and attacks. -More information about each referenced dataset can be found in the [datasets](datasets.md) document. - - -### Audio ASR (Updated June 2022) -* **Description:** -In this scenario, the system under evaluation is an automatic speech recognition system. -* **Dataset:** - * Armory includes one dataset suited for ASR: - * [LibriSpeech dataset](http://www.openslr.org/12) (custom subset) -* **Baseline Models:** -Armory includes two audio models: - * [DeepSpeech 2](https://arxiv.org/pdf/1512.02595v1.pdf) with pretrained weights from either the AN4, LibriSpeech, or TEDLIUM datasets. - Custom weights may also be loaded by the model. *Deprecated: will be removed in version 0.17.0* - * [HuBERT](https://arxiv.org/abs/2106.07447) Large from [torchaudio](https://pytorch.org/audio/0.10.0/pipelines.html#torchaudio.pipelines.Wav2Vec2Bundle) -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary may simply wish for speech to be transcribed incorrectly - * Targeted - an adversary may wish for specific strings to be predicted - * Contradiction: an adversary may wish to transcribe a specific string with a meaning contrary to the original, albeit with a low word error rate. - * Adversary Operating Environment: - * Non-real time, digital evasion attack. - * Under some threat models, the channel model consists only a single perfect acoustic channel, and under others, it may consist of one additional multipath channel. -* **Metrics of Interest:** - * Primary metrics: - * Word error rate, SNR, entailment rate - * Derivative metrics - see end of document -* **Baseline Attacks:** - * [Imperceptible ASR attack](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/imperceptible_asr/imperceptible_asr.py) - * [PGD](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/projected_gradient_descent/projected_gradient_descent.py) - * [Kenansville attack](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/art_experimental/attacks/kenansville_dft.py) -* **Baseline Defense**: [MP3 Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/mp3_compression.py) -* **Baseline Evaluations:** - * [LibriSpeech results](baseline_results/librispeech_asr_results.md) - - -### Audio Classification (Updated June 2020) -* **Description:** -In this scenario, the system under evaluation is a speaker identification system. -* **Dataset:** - * Armory includes one dataset suited for Audio Classification: - * [LibriSpeech dataset](http://www.openslr.org/12) (custom subset): -* **Baseline Model:** - * Armory includes two baseline speaker classification models: - * [SincNet](https://arxiv.org/abs/1808.00158), a scratch-trained model based on raw audio - * A scratch-trained model based on spectrogram input (not mel-cepstrum or MFCC) -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary may simply wish to evade detection - * Targeted - an adversary may wish to impersonate someone else - * Adversary Operating Environment: - * Non-real time, digital evasion attack - * Assuming perfect acoustic channel - * Black-box, white-box, and adaptive attacks -* **Metrics of Interest:** - * Primary metrics: - * Accuracy (mean, per-class), attack computational cost, defense computational cost, various distance measures of perturbation - (Lp-norms, Wasserstein distance, signal-to-noise ratio) - * Derivative metrics - see end of document -* **Baseline Evaluations:** - * [LibriSpeech results](baseline_results/librispeech_audio_classification_results.md) - - -### CARLA Multi-Object tracking (MOT) (Updated October 2022) -* **Description:** -In this scenario specific to the CARLA multi-object tracking dataset, the system under evaluation is an object tracker -trained to track multiple pedestrians in video in an urban environment. -* **Dataset:** -The development dataset is the [CARLA](https://carla.org) Multi-Object Tracking dataset, with videos containing a green-screen in all frames intended for adversarial patch insertion. -The dataset contains natural lighting metadata that allow digital, adaptive patches to be inserted and rendered into the scene similar to if they were physically printed. -* **Baseline Model:** - * Pretrained [ByteTrack](https://arxiv.org/pdf/2110.06864.pdf) model with an [Faster-RCNN](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/carla_mot_frcnn_byte.py) base instead of Yolo. -* **Threat Scenario:** - * Adversary objectives: - * To degrade the performance of the tracker through the insertion of adversarial patches. - * Adversary Operating Environment: - * Non-real time, physical-like patch attacks -* Adversary Capabilities and Resources - * Patch size of different size/shape as dictated by the green-screen in the frames. The adversary is expected to apply a patch with constant texture across all frames in the video, but the patch relative to the sensor may change due to sensor motion. -* **Metrics of Interest:** - * Primary metrics are [HOTA](https://link.springer.com/article/10.1007/s11263-020-01375-2)-based (quotes taken from paper), taken from [TrackEval](https://github.com/JonathonLuiten/TrackEval) implementation. - * mean DetA - "detection accuracy, DetA, is simply the percentage of aligning detections" - * mean AssA - "association accuracy, AssA, is simply the average alignment between matched trajectories, averaged over all detections" - * mean HOTA - "final HOTA score is the geometric mean of these two scores averaged over different localisation thresholds" -* **Baseline Attacks:** - * [Custom Robust DPatch with Non-differentiable, Input-Dependent Transformation](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/attacks/carla_obj_det_patch.py) - * [Custom Adversarial Patch with Differentiable, Input-Dependent Transformation](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/attacks/carla_obj_det_adversarial_patch.py) -* **Baseline Defense**: [JPEG Frame Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/jpeg_compression.py) -* **Baseline Evaluation**: [Carla MOT results](baseline_results/carla_mot_results.md) - - -### CARLA Multimodal Object Detection (Updated October 2022) -* **Description:** -In this scenario, the system under evaluation is an object detector trained to identify common objects in an urban environment. This scenario handles multimodal data (RGB/depth). -* **Datasets** - The datasets are the [CARLA](https://carla.org) Object Detection and Overhead Object Detection datasets. - These datasets contain natural lighting metadata that allow digital, adaptive patches to be inserted and rendered into the scene similar to if they were physically printed. -* **Baseline Model:** - * Single-modality: - * Pretrained [Faster-RCNN with ResNet-50](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/carla_single_modality_object_detection_frcnn.py) model. - * Multimodal: - * Pretrained multimodal [Faster-RCNN with ResNet-50](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/carla_multimodality_object_detection_frcnn.py) model. -* **Threat Scenario:** - * Adversary objectives: - * To degrade the performance of an object detector through the insertion of adversarial patches. - * Adversary Operating Environment: - * Non-real time, physical-like patch attacks -* Adversary Capabilities and Resources - * Patch size of different size/shape as dictated by the green-screen in each image. In the multimodal case, both RGB and depth channels are to be perturbed. -* **Metrics of Interest:** - * Primary metrics: - * mAP - * Disappearance rate - * Hallucinations per image - * Misclassification rate - * True positive rate -* **Baseline Attacks:** - * [Custom Robust DPatch with Non-differentiable, Input-Dependent Transformation](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/art_experimental/attacks/carla_obj_det_patch.py) - * [Custom Adversarial Patch with Differentiable, Input-Dependent Transformation](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/art_experimental/attacks/carla_obj_det_adversarial_patch.py) -* **Baseline Defense**: [JPEG Compression](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/art_experimental/defences/jpeg_compression_normalized.py) -* **Baseline Evaluations**: - * [Street-level dataset](baseline_results/carla_od_results.md#carla-street-level-od-dataset) - * [Overhead dataset](baseline_results/carla_od_results.md#carla-overhead-od-dataset) - - -### CARLA Video Tracking (Updated July 2022) -* **Description:** -In this scenario, the system under evaluation is an object tracker trained to localize a single moving pedestrian. -* **Dataset:** -The development dataset is the [CARLA Video Tracking dataset](https://carla.org), which includes 20 videos, each of -which contains a green-screen in all frames intended for adversarial patch insertion. The dataset contains natural lighting metadata that allow digital, adaptive patches to be inserted and rendered into the scene similar to if they were physically printed. -* **Baseline Model:** - * Pretrained [GoTurn](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/carla_goturn.py) model. -* **Threat Scenario:** - * Adversary objectives: - * To degrade the performance of the tracker through the insertion of adversarial patches. - * Adversary Operating Environment: - * Non-real time, physical-like patch attacks -* Adversary Capabilities and Resources - * Patch size of different size/shape as dictated by the green-screen in the frames. The adversary is expected to apply a patch with constant texture across all frames in the video, but the patch relative to the sensor may change due to sensor motion. -* **Metrics of Interest:** - * Primary metrics: - * mean IOU - * mean succss rate (mean IOUs are calculated for multiple IOU thresholds and averaged) -* **Baseline Attacks:** - * [Custom Adversarial Texture with Input-Dependent Transformation](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/art_experimental/attacks/carla_adversarial_texture.py) -* **Baseline Defense**: [Video Compression](https://github.com/twosixlabs/armory/blob/v0.15.2/armory/art_experimental/defences/video_compression_normalized.py) -* **Baseline Evaluation**: [CARLA video tracking results](baseline_results/carla_video_tracking_results.md) - - -### Dapricot Object Detection (Updated July 2021) -* **Description:** -In this scenario, the system under evaluation is an object detector trained to identify the classes in the [Microsoft COCO dataset](https://arxiv.org/pdf/1405.0312.pdf). -* **Dataset:** -The dataset is the [Dynamic APRICOT (DAPRICOT) dataset 1](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/data/adversarial/dapricot_dev.py) and [dataset 2](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/data/adversarial/dapricot_test.py). It is similar to the APRICOT dataset (see below), but instead of pre-generated physical patches taken in the natural environment, the DAPRICOT dataset contains greenscreens and natural lighting metadata that allow digital, adaptive patches to be inserted and rendered into the scene similar to if they were physically printed. This dataset contains 15 scenes, where each scene contains 3 different greenscreen shapes, taken at 3 different distances, 3 different heights and using 3 different camera angles, for a total of over 1000 images. -* **Baseline Model:** -The model uses the pretrained [Faster-RCNN with ResNet-50](https://github.com/tensorflow/models/blob/master/research/object_detection/g3doc/tf1_detection_zoo.md) model. -* **Threat Scenario:** - * Adversary objectives: - * Targeted attack - objective is to force an object detector to localize and classify the patch as an MSCOCO object. - * Adversary Operating Environment: - * Non-real time, digital and physical-like patch attacks -* Adversary Capabilities and Resources - * Patch size of different shapes as dictated by the greenscreen sizes in the images -* **Metrics of Interest:** - * Primary metrics: - * Average precision (mean, per-class) of patches, Average target success -* **Baseline Attacks:** - * [Masked PGD](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/projected_gradient_descent/projected_gradient_descent.py) - * [Robust DPatch](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/dpatch_robust.py) -* **Baseline Defense:** [JPEG Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/jpeg_compression.py) -* **Baseline Evaluation:** [Dapricot results](baseline_results/dapricot_results.md) - -### Image Classification -* **Description:** -In this scenario implements attacks against a basic image classification task. -* **Dataset:** - * Armory includes several image classification datasets. - * [Resisc-45](http://www.escience.cn/people/JunweiHan/NWPU-RESISC45.html). It comprises 45 classes and 700 images for each class. Images 1-500 of each class are in the training split, -500-600 are in the validation split, and 600-700 are in the test split. - * MNIST - * Cifar10 -* **Baseline Models:** - * Armory includes the following baseline image classification models: - * Resisc-45: ImageNet-pretrained DenseNet-121 that is fine-tuned on RESISC-45. - * MNIST: basic CNN - * Cifar10: basic CNN -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary may simply wish to induce an arbitrary misclassification - * Targeted - an adversary may wish to force misclassification to a particular class - * Adversary Operating Environment: - * Non real-time, digital evasion attack - * Black-box, white-box, and adaptive attacks -* **Metrics of Interest:** - * Primary metrics: - * Accuracy (mean, per-class), attack computational cost, defense computational cost, various distance measures of perturbation - (Lp-norms, Wasserstein distance) - * Derivative metrics - see end of document -* **Baseline Defenses:** - * [JPEG Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/jpeg_compression.py) -* **Baseline Evaluations:** - * [Resisc-45 results](baseline_results/resisc45_results.md) - - -### Multimodal So2Sat Image Classification (Updated July 2021) -* **Description:** -In this scenario, the system under evaluation is an image classifier which determines local climate zone from a combination of co-registered synthetic aperture radar (SAR) and multispectral electro-optical (EO) images. This Image Classification task gets its own scenario due to the unique features of the dataset. -* **Dataset:** -The dataset is the [so2sat dataset](https://mediatum.ub.tum.de/1454690). It comprises 352k/24k images in -train/validation datasets and 17 classes of local climate zones. -* **Baseline Model:** - * Armory includes a custom CNN as a baseline model. It has a single input that stacks SAR (first four channels only, -representing the real and imaginary components of the reflected electromagnetic waves) -and EO (all ten channels) data. Immediately after the input layer, the data is split into SAR and EO data -streams and fed into their respective feature extraction networks. In the final layer, the two -networks are fused to produce a single prediction output. -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary wishes to evade correct classification - * Adversary Operating Environment: - * Non-real time, digital evasion attack - * Adversary perturbs a single modality (SAR or EO) -* **Metrics of Interest:** - * Primary metrics: - * Accuracy (mean, per-class), Patch size - * Derivative metrics - see end of document -* **Baseline Attacks:** - * [Masked PGD](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/projected_gradient_descent/projected_gradient_descent.py) -* **Baseline Defense:** [JPEG Compression for Multi-Channel](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/art_experimental/defences/jpeg_compression_multichannel_image.py) -* **Baseline Evaluation:** [So2Sat results](baseline_results/so2sat_results.md) - - -### Object Detection -* **Description:** -In this scenario, the system under evaluation is an object detector. -* **Datasets:** - * Armory includes two datasets for object detection (besides CARLA object detection which has its own [scenario](#carla-multimodal-object-detection-updated-october-2022)): - * [xView](https://arxiv.org/pdf/1802.07856) comprises 59k/19k train and test -images (each with dimensions 300x300, 400x400 or 500x500) and 62 classes - * [APRICOT](https://arxiv.org/pdf/1912.08166.pdf), which includes over 1000 natural images with physically-printed adversarial patches, with ten MS-COCO classes as targets -* **Baseline Models:** - * [Faster-RCNN ResNet-50 FPN](https://arxiv.org/pdf/1506.01497.pdf), pre-trained, can be used for xView - * [Faster-RCNN with ResNet-50, SSD with MobileNet, and RetinaNet](https://github.com/tensorflow/models/blob/master/research/object_detection/g3doc/tf1_detection_zoo.md) models, pretrained, can be used for APRICOT. -on MSCOCO objects and fine-tuned on xView. -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary wishes to disable object detection - * Adversary Operating Environment: - * Non-real time, digital and physical-like evasion attacks - and translation. - * Note: the APRICOT dataset consists of advesarial images precomputed for a targeted attack. -* **Metrics of Interest:** - * Primary metrics: - * Average precision (mean, per-class) of ground truth classes, Patch Size - * Derivative metrics - see end of document -* **Baseline Attacks:** - * [Masked PGD](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/projected_gradient_descent/projected_gradient_descent.py) - * [Robust DPatch](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/dpatch_robust.py) - * The patches for APRICOT were generated using variants of [ShapeShifter](https://arxiv.org/abs/1804.05810) -* **Baseline Defense:** [JPEG Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/jpeg_compression.py) -* **Baseline Evaluations**: - * [xView results](baseline_results/xview_results.md) - * [APRICOT results](baseline_results/apricot_results.md) - -### UCF101 Video Classification - -* **Description:** -In this scenario, the system under evaluation is a video action recognition system. -* **Datasets:** -Armory includes the following video classification datasets: - * [UCF101 dataset](https://www.crcv.ucf.edu/data/UCF101.php), which comprises 101 actions and 13,320 total videos. For the training/testing split, -we use the official Split 01. -* **Baseline Model:** -Armory includes a model for UCF101 that uses the [MARS architecture](http://openaccess.thecvf.com/content_CVPR_2019/papers/Crasto_MARS_Motion-Augmented_RGB_Stream_for_Action_Recognition_CVPR_2019_paper.pdf), -which is a single-stream (RGB) 3D convolution architecture that simultaneously mimics the optical flow stream. -The provided model is pre-trained on the Kinetics dataset and fine-tuned on UCF101. -* **Threat Scenario:** - * Adversary objectives: - * Untargeted - an adversary may simply wish to evade detection - * Adversary Operating Environment: - * Non-real time, digital evasion attack -* **Metrics of Interest:** - * Primary metrics: - * Accuracy (mean, per-class), attack budget - * Derivative metrics - see end of document -* **Baseline Attacks:** - * [Frame Saliency](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/frame_saliency.py) - * [Masked PGD](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/projected_gradient_descent/projected_gradient_descent.py) - * [Flicker Attack](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/attacks/evasion/over_the_air_flickering/over_the_air_flickering_pytorch.py) - * [Custom Frame Border attack](https://github.com/twosixlabs/armory/blob/8eb10ac43bf4382d69625d8cef8a3e8cb23d0318/armory/art_experimental/attacks/video_frame_border.py) -* **Baseline Defense:** [Video Compression](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/preprocessor/video_compression.py) -* **Baseline Evaluations:** - * [UCF101 results](baseline_results/ucf101_results.md) - - -### Poisoning - -For a complete overview of the poisoning scenarios, threat models, attacks, and metrics, see the [poisoning doc](poisoning.md). Here, we will briefly summarize each scenario and link to the baseline results. - -#### Poison base scenario (DLBD) - -* **Description:** The base scenario implements a Dirty-label Backdoor attack (DLBD). In this scenario, the attacker is able to poison a percentage of the training data by adding backdoor triggers and flipping the label of data examples. Then, the attacker adds the same trigger to test images to cue the desired misclassification. For a complete overview, see the [poisoning doc](poisoning.md). -* **Datasets:** - Datasets for DLBD include but are not limited to: - * GTSRB - * Audio Speech Commands - * Resisc-10 - * Cifar10 -* **Baseline Models:** - Armory includes several models which may be used for this scenario: - * [GTSRB micronnet](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/micronnet_gtsrb.py) - * [Audio resnet](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/tf_graph/audio_resnet50.py) - * [Resnet18](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/resnet18.py) can be used for Cifar10 or Resisc-10 -* **Threat Scenario:** - * Adversary objectives: - * Targeted misclassification - * Adversary Operating Environment: - * Non-real time, digital evasion attack -* **Metrics of Interest:** See the [poisoning doc](poisoning.md) for a full description of these metrics. - * accuracy_on_benign_test_data_all_classes - * accuracy_on_benign_test_data_source_class - * accuracy_on_poisoned_test_data_all_classes - * attack_success_rate - * Model Bias fairness metric - * Filter Bias fairness metric -* **Baseline Defenses:** - * [Activation Clustering](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/activation_defence.py) - * [Spectral Signatures](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/spectral_signature_defense.py) - * [Random Filter](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/poison_detection/random_filter.py) - * [Perfect Filter](https://github.com/twosixlabs/armory/blob/1d6caa9166313c1409edbbc5f089d2bc774b5230/armory/scenarios/poison.py#L233-L235) -* **Baseline Evaluations:** - * [GTSRB DLBD](baseline_results/gtsrb_dlbd_results.md) - * [Resisc DLBD](baseline_results/resisc_dlbd_results.md) - * [Audio](baseline_results/speech_commands_poison_results.md) - * [Cifar10](baseline_results/cifar10_dlbd.md) - - -#### Poisoning CLBD -* **Description:** This scenario implements a Clean-label Backdoor attack (CLBD). In this scenario, the attacker adds triggers to source class training images, leaving the labels the same but also applying imperceptible perturbations that look like target class features. At test time, adding the trigger to a source class image induces misclassification to the target class. For a complete overview, see the [poisoning doc](poisoning.md). -* **Datasets:** - Datasets for CLBD include but are not limited to: - * GTSRB -* **Baseline Models:** - Armory includes several models which may be used for this scenario: - * [GTSRB micronnet](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/micronnet_gtsrb.py) - * [Resnet18](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/resnet18.py) -* **Threat Scenario:** - * Adversary objectives: - * Targeted misclassification - * Adversary Operating Environment: - * Non-real time, digital evasion attack -* **Metrics of Interest:** See the [poisoning doc](poisoning.md) for a full description of these metrics. - * accuracy_on_benign_test_data_all_classes - * accuracy_on_benign_test_data_source_class - * accuracy_on_poisoned_test_data_all_classes - * attack_success_rate - * Model Bias fairness metric - * Filter Bias fairness metric -* **Baseline Defenses:** - * [Activation Clustering](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/activation_defence.py) - * [Spectral Signatures](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/spectral_signature_defense.py) - * [Random Filter](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/poison_detection/random_filter.py) - * [Perfect Filter](https://github.com/twosixlabs/armory/blob/1d6caa9166313c1409edbbc5f089d2bc774b5230/armory/scenarios/poison.py#L233-L235) -* **Baseline Evaluations:** - * [GTSRB](baseline_results/gtsrb_clbd_results.md) - * [Resisc CLBD](baseline_results/resisc_clbd_results.md) - - -#### Poisoning: Sleeper Agent -* **Description:** This scenario implements the Sleeper Agent attack. In this scenario, the attacker poisons train samples through gradient matching, then applies a trigger to test images to induce misclassification. -For a complete overview, see the [poisoning doc](poisoning.md). -* **Datasets:** - Datasets for Sleeper Agent include but are not limited to: - * Cifar10 -* **Baseline Models:** - Armory includes several models which may be used for this scenario: -* [Resnet18](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/resnet18.py) -* **Threat Scenario:** - * Adversary objectives: - * Targeted misclassification - * Adversary Operating Environment: - * Non-real time, digital evasion attack -* **Metrics of Interest:** See the [poisoning doc](poisoning.md) for a full description of these metrics. - * accuracy_on_benign_test_data_all_classes - * accuracy_on_benign_test_data_source_class - * accuracy_on_poisoned_test_data_all_classes - * attack_success_rate - * Model Bias fairness metric - * Filter Bias fairness metric -* **Baseline Defenses:** - * [Activation Clustering](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/activation_defence.py) - * [Spectral Signatures](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/spectral_signature_defense.py) - * [Random Filter](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/poison_detection/random_filter.py) - * [Perfect Filter](https://github.com/twosixlabs/armory/blob/1d6caa9166313c1409edbbc5f089d2bc774b5230/armory/scenarios/poison.py#L233-L235) -* **Baseline Evaluations:** - * [Cifar results](baseline_results/cifar10_sleeper_agent.md) - - -#### Poisoning: Witches' Brew -* **Description:** This scenario implements the Witches' Brew attack. In this scenario, the attacker poisons train samples through gradient matching, to induce misclassification on a few individual pre-chosen test images. For a complete overview, see the [poisoning doc](poisoning.md). -* **Datasets:** - The following datasets have been successfully used in this scenario: - * GTSRB - * Cifar10 -* **Baseline Models:** - Armory includes several models which may be used for this scenario: - * [GTSRB micronnet](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/micronnet_gtsrb.py) - * [Resnet18](https://github.com/twosixlabs/armory/blob/master/armory/baseline_models/pytorch/resnet18.py) -* **Threat Scenario:** - * Adversary objectives: - * Targeted misclassification - * Adversary Operating Environment: - * Non-real time, digital evasion attack -* **Metrics of Interest:** See the [poisoning doc](poisoning.md) for a full description of these metrics. - * accuracy_on_trigger_images - * accuracy_on_non_trigger_images - * attack_success_rate - * Model Bias fairness metric - * Filter Bias fairness metric -* **Baseline Defenses:** - * [Activation Clustering](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/activation_defence.py) - * [Spectral Signatures](https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/art/defences/detector/poison/spectral_signature_defense.py) - * [Random Filter](https://github.com/twosixlabs/armory/blob/master/armory/art_experimental/poison_detection/random_filter.py) - * [Perfect Filter](https://github.com/twosixlabs/armory/blob/1d6caa9166313c1409edbbc5f089d2bc774b5230/armory/scenarios/poison.py#L233-L235) -* **Baseline Evaluations:** - * [Cifar10 results](baseline_results/cifar10_witches_brew_results.md) - * [GTSRB results](baseline_results/gtsrb_witches_brew_results.md) - - -## Creating a new scenario -Users may want to create their own scenario, because the baseline scenarios do -not fit the requirements of some defense/threat-model, or because it may be easier -to debug in code that you have access to as opposed to what is pre-installed by the -armory package. - -To do so, simply inherit the scenario class and override the necessary functions. -An [example of doing this](https://github.com/twosixlabs/armory-example/blob/master/example_scenarios/audio_spectrogram_classification.py) can be found in our armory-examples repo. diff --git a/docs/original/sweep_attacks.md b/docs/original/sweep_attacks.md deleted file mode 100644 index 519c56d1b..000000000 --- a/docs/original/sweep_attacks.md +++ /dev/null @@ -1,87 +0,0 @@ -# Sweep Attacks - -Armory supports running adversarial attacks which "sweep" over a range of values for specified -attack parameters (e.g. `"eps"`). This helps automate the process of determining at what -attack parameter values (i.e. perturbation budget) a defense is no longer robust. The attack -returns the weakest-strength adversarial example that is successful, or the original input -if the attack fails at all values. - -To enable such an attack, set `attack_config["type"]` to `"sweep"`. -```aidl -"attack": { - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - ... - "type": "sweep" -} -``` - -Next, specify which parameter(s) to perform the search over. This is done using the -`attack_config["sweep_params"]["kwargs"]` field for kwargs passed to attack instantiation and the -`attack_config["sweep_params"]["generate_kwargs"]` field for kwargs passed to the attack's -`generate()` method. In the example below we sweep over the `"eps"` and `"eps_step"` -parameters: - -```aidl -"attack": { - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "type": "sweep", - "sweep_params": { - "kwargs": { - "eps": [0.01, 0.02, 0.03, 0.04, 0.05, 0.06, 0.07, 0.08], - "eps_step": [0.005, 0.01, 0.015, 0.02, 0.025, 0.03, 0.035, 0.04] - } - } -} -``` - -Similarly, in the following example, we sweep over kwargs passed to the attack's `generate()` method -using the `"generate_kwargs"` field inside `attack_config["sweep_params"]`: -```aidl -"attack": { - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "type": "sweep", - "sweep_params": { - "generate_kwargs": { - "patch_height": [10, 20, 30, 40, 50], - "patch_width": [10, 20, 30, 40, 50] - } - } -} -``` - -Each range of sweep parameters must be specified with a list of length `N`, where `N > 1` is -the number of desired search points. All parameters specified inside of -`attack_config["sweep_params"]` must correspond to lists of length `N`, and the `ith` element of -a given kwarg list will be used in conjunction with the `ith` element of all other kwarg -lists (i.e. in the first example, when `"eps"` is `0.01`, `"eps_step"` is `0.005` and so on). The -search algorithm assumes that parameters lists are in ascending order of attack strength. - -Attack parameters to be held constant should be specified in `attack_config["kwargs"]` and -`attack_config["generate_kwargs"]` as per usual. If the same kwarg (or generate_kwarg) appears in `attack_config["kwargs"]` -and `attack_config["sweep_params"]["kwargs"]`, the former will be ignored. - - -### Determining Attack Success -In order to identify at what point an attack is successful, it is necessary to define how -attack success is measured. By default `armory.utils.metrics.categorical_accuracy` is used to -determine whether the predicted label matches the ground-truth. For non-classification -scenarios such as object detection or speech recognition, this metric doesn't apply. - -Users can specify the task-relevant metric used to measure robustness via the -`attack_config["sweep_params"]["metric"]` field. Inside this field, specify a `"module"` and -`"name"` which point to the desired metric function. This can be any function `f` which takes -positional arguments `y` and `y_pred` as such: `f(y, y_pred)` and returns a scalar. A -`"threshold"` must also be specified indicating at what metric value that attack is -considered successful. For non-targeted attacks, if the value is *below* the threshold we -consider the attack successful, while the opposite is true for targeted attacks. - -### Additional Configuration Settings -Sweep attacks require access to either ground-truth or target labels `y`. If the attack -is untargeted, set `attack_config["use_label"]` to `true`. - - -To ensure that metrics are saved on a per-example basis, set -`metric_config["record_metric_per_sample"]` to `true`. diff --git a/docs/scenario_configs/README.md b/docs/scenario_configs/README.md deleted file mode 100644 index 48cfa3e0e..000000000 --- a/docs/scenario_configs/README.md +++ /dev/null @@ -1 +0,0 @@ -These config files were used by Armory prior to version 23.03. They are here for historical reference. diff --git a/docs/scenario_configs/asr_librispeech_entailment.json b/docs/scenario_configs/asr_librispeech_entailment.json deleted file mode 120000 index 752937374..000000000 --- a/docs/scenario_configs/asr_librispeech_entailment.json +++ /dev/null @@ -1 +0,0 @@ -eval5/asr_librispeech/entailment.json \ No newline at end of file diff --git a/docs/scenario_configs/asr_librispeech_targeted.json b/docs/scenario_configs/asr_librispeech_targeted.json deleted file mode 120000 index 04b2e2ac6..000000000 --- a/docs/scenario_configs/asr_librispeech_targeted.json +++ /dev/null @@ -1 +0,0 @@ -eval5/asr_librispeech/untargeted_snr_pgd.json \ No newline at end of file diff --git a/docs/scenario_configs/carla_multimodal_object_detection.json b/docs/scenario_configs/carla_multimodal_object_detection.json deleted file mode 120000 index be7f1e7cc..000000000 --- a/docs/scenario_configs/carla_multimodal_object_detection.json +++ /dev/null @@ -1 +0,0 @@ -eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json \ No newline at end of file diff --git a/docs/scenario_configs/carla_video_tracking.json b/docs/scenario_configs/carla_video_tracking.json deleted file mode 120000 index 0728282fa..000000000 --- a/docs/scenario_configs/carla_video_tracking.json +++ /dev/null @@ -1 +0,0 @@ -eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_undefended.json \ No newline at end of file diff --git a/docs/scenario_configs/cifar10_baseline.json b/docs/scenario_configs/cifar10_baseline.json deleted file mode 120000 index 43df4eda5..000000000 --- a/docs/scenario_configs/cifar10_baseline.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/cifar/cifar10_baseline.json \ No newline at end of file diff --git a/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn.json b/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn.json deleted file mode 100644 index 426cefe44..000000000 --- a/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn.json +++ /dev/null @@ -1,54 +0,0 @@ -{ - "_description": "APRICOT object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "split": "frcnn+ssd+retinanet" - }, - "module": "armory.data.adversarial_datasets", - "name": "apricot_dev_adversarial", - "type": "preloaded", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "frcnn+ssd+retinanet", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "apricot_dev_adversarial" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "apricot_patch_targeted_AP_per_class", - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.mscoco_frcnn", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn_defended.json b/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn_defended.json deleted file mode 100644 index ad327a315..000000000 --- a/docs/scenario_configs/eval1-4/aprioct/apricot_frcnn_defended.json +++ /dev/null @@ -1,67 +0,0 @@ -{ - "_description": "APRICOT object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "split": "frcnn+ssd+retinanet" - }, - "module": "armory.data.adversarial_datasets", - "name": "apricot_dev_adversarial", - "type": "preloaded", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "frcnn+ssd+retinanet", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "apricot_dev_adversarial" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 10 - }, - "module": "armory.art_experimental.defences.jpeg_compression_normalized", - "name": "JpegCompressionNormalized", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "apricot_patch_targeted_AP_per_class", - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.mscoco_frcnn", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_defended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_defended.json deleted file mode 100644 index cdecb16ce..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_defended.json +++ /dev/null @@ -1,92 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "decrease_factor_alpha": 0.5, - "decrease_factor_eps": 0.5, - "eps": 0.0075, - "global_max_length": 562480, - "increase_factor_alpha": 2.0, - "initial_rescale": 1.0, - "learning_rate_1": 0.0001, - "learning_rate_2": 1e-07, - "max_iter_1": 400, - "max_iter_2": 100, - "num_iter_decrease_alpha": 50 - }, - "module": "art.attacks.evasion.imperceptible_asr.imperceptible_asr_pytorch", - "name": "ImperceptibleASRPyTorch", - "targeted": true, - "targeted_labels": { - "scheme": "matched length", - "transcripts": [ - "REALLY SHORT TEST STRING", - "THE TEST STRING HAS A LENGTH EQUAL TO THE MEDIAN OF THE CLEAN TEST TRANSCRIPT LENGTHS", - "THIS IS AN EXCEEDINGLY LONG TEST STRING BUT NOT REALLY AS THE LONGEST STRING HAS OVER FIVE HUNDRED CHARACTERS IN ITS TRANSCRIPT AND INCLUDES A LIST OF PEOPLE AND SPEAKS OF A SENATOR FROM NEW JERSEY" - ] - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3CompressionPyTorch", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_undefended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_undefended.json deleted file mode 100644 index 71b02f0dc..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_imperceptible_undefended.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "decrease_factor_alpha": 0.5, - "decrease_factor_eps": 0.5, - "eps": 0.0075, - "global_max_length": 562480, - "increase_factor_alpha": 2.0, - "initial_rescale": 1.0, - "learning_rate_1": 0.0001, - "learning_rate_2": 1e-07, - "max_iter_1": 400, - "max_iter_2": 100, - "num_iter_decrease_alpha": 50 - }, - "module": "art.attacks.evasion.imperceptible_asr.imperceptible_asr_pytorch", - "name": "ImperceptibleASRPyTorch", - "targeted": true, - "targeted_labels": { - "scheme": "matched length", - "transcripts": [ - "REALLY SHORT TEST STRING", - "THE TEST STRING HAS A LENGTH EQUAL TO THE MEDIAN OF THE CLEAN TEST TRANSCRIPT LENGTHS", - "THIS IS AN EXCEEDINGLY LONG TEST STRING BUT NOT REALLY AS THE LONGEST STRING HAS OVER FIVE HUNDRED CHARACTERS IN ITS TRANSCRIPT AND INCLUDES A LIST OF PEOPLE AND SPEAKS OF A SENATOR FROM NEW JERSEY" - ] - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_defended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_defended.json deleted file mode 100644 index c4d41fb71..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_defended.json +++ /dev/null @@ -1,75 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "partial_attack": false, - "snr_db": 20, - "targeted": false - }, - "module": "armory.art_experimental.attacks.kenansville_dft", - "name": "KenansvilleDFT", - "use_label": false - }, - "dataset": { - "batch_size": 8, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3Compression", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_undefended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_undefended.json deleted file mode 100644 index 1a8e25bed..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_kenansville_undefended.json +++ /dev/null @@ -1,64 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "partial_attack": false, - "snr_db": 20, - "targeted": false - }, - "module": "armory.art_experimental.attacks.kenansville_dft", - "name": "KenansvilleDFT", - "use_label": false - }, - "dataset": { - "batch_size": 8, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_defended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_defended.json deleted file mode 100644 index c54f8ef78..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_defended.json +++ /dev/null @@ -1,86 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.5, - "eps_step": 0.05, - "max_iter": 100, - "norm": 2, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3Compression", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_multipath_channel_undefended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_multipath_channel_undefended.json deleted file mode 100644 index ac814e83a..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_multipath_channel_undefended.json +++ /dev/null @@ -1,80 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "audio_channel": { - "attenuation": 0.5, - "delay": 300, - "pytorch": true - }, - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.5, - "eps_step": 0.05, - "max_iter": 100, - "norm": 2, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_undefended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_undefended.json deleted file mode 100644 index 94a7bef1c..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_pgd_undefended.json +++ /dev/null @@ -1,75 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.5, - "eps_step": 0.05, - "max_iter": 100, - "norm": 2, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_targeted.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_targeted.json deleted file mode 100644 index 263adccac..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_targeted.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 10, - "eps_step": 0.5, - "max_iter": 10, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "import_from": "armory.attacks.librispeech_target_labels", - "transcripts": "matched_length" - }, - "module": "armory.utils.labels", - "name": "MatchedTranscriptLengthTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_undefended.json b/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_undefended.json deleted file mode 100644 index 9ed517ef0..000000000 --- a/docs/scenario_configs/eval1-4/asr_librispeech/librispeech_asr_snr_undefended.json +++ /dev/null @@ -1,80 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 10, - "eps_step": 0.5, - "max_iter": 10, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "value": "TEST STRING" - }, - "module": "armory.utils.labels", - "name": "FixedStringTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/cifar/cifar10_baseline.json b/docs/scenario_configs/eval1-4/cifar/cifar10_baseline.json deleted file mode 100644 index 9e9adc5d9..000000000 --- a/docs/scenario_configs/eval1-4/cifar/cifar10_baseline.json +++ /dev/null @@ -1,59 +0,0 @@ -{ - "_description": "Baseline cifar10 image classification", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.031, - "eps_step": 0.007, - "max_iter": 20, - "num_random_init": 1, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "use_label": true - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.cifar", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/dapricot/dapricot_frcnn_masked_pgd.json b/docs/scenario_configs/eval1-4/dapricot/dapricot_frcnn_masked_pgd.json deleted file mode 100644 index 77a0ac11b..000000000 --- a/docs/scenario_configs/eval1-4/dapricot/dapricot_frcnn_masked_pgd.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "DAPRICOT object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "threat_model": "digital" - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.02, - "max_iter": 100, - "targeted": true - }, - "module": "armory.art_experimental.attacks.dapricot_patch", - "name": "DApricotMaskedPGD", - "targeted_labels": { - "scheme": "object_detection_fixed", - "value": 2 - } - }, - "dataset": { - "batch_size": 1, - "eval_split": "large+medium+small", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "dapricot_test_adversarial" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "dapricot_patch_targeted_AP_per_class", - "dapricot_patch_target_success" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.mscoco_frcnn", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": true, - "kwargs": {}, - "module": "armory.scenarios.dapricot_scenario", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/mnist/mnist_baseline.json b/docs/scenario_configs/eval1-4/mnist/mnist_baseline.json deleted file mode 100644 index 6f8988de4..000000000 --- a/docs/scenario_configs/eval1-4/mnist/mnist_baseline.json +++ /dev/null @@ -1,57 +0,0 @@ -{ - "_description": "Baseline mnist image classification", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "use_label": true - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.mnist", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd.json b/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd.json deleted file mode 100644 index 582f60254..000000000 --- a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd.json +++ /dev/null @@ -1,66 +0,0 @@ -{ - "_description": "GTSRB poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "pattern" - }, - "eps": 2.6, - "eps_step": 0.1, - "max_iter": 100, - "n_classes": 43, - "norm": 2, - "num_random_init": 0, - "pp_poison": 0.1, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_bullethole.json b/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_bullethole.json deleted file mode 100644 index 568fa9d35..000000000 --- a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_bullethole.json +++ /dev/null @@ -1,71 +0,0 @@ -{ - "_description": "GTSRB poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 50, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 17, - 15 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 2, - "pp_poison": 0.5, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_defended.json b/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_defended.json deleted file mode 100644 index 231fe90e5..000000000 --- a/docs/scenario_configs/eval1-4/poisoning/gtsrb_scenario_clbd_defended.json +++ /dev/null @@ -1,77 +0,0 @@ -{ - "_description": "GTSRB poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "pattern" - }, - "eps": 2.6, - "eps_step": 0.1, - "max_iter": 100, - "n_classes": 43, - "norm": 2, - "num_random_init": 0, - "pp_poison": 0.1, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/poisoning/resisc10_poison_dlbd.json b/docs/scenario_configs/eval1-4/poisoning/resisc10_poison_dlbd.json deleted file mode 100644 index 547691db9..000000000 --- a/docs/scenario_configs/eval1-4/poisoning/resisc10_poison_dlbd.json +++ /dev/null @@ -1,121 +0,0 @@ -{ - "_description": "RESISC10 poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "resisc10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 5, - "train_epochs": 200, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "letter_A.png", - "base_img_size_x": 64, - "base_img_size_y": 64, - "blend": 0.8, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 10, - 10 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc10" - }, - "defense": { - "data_augmentation": { - "rotation": { - "kwargs": { - "apply_fit": false, - "apply_predict": false, - "clip_values": [ - 0.0, - 1.0 - ], - "degree": 0.0, - "nb_samples": 1, - "scale": [ - 0.8, - 1.2 - ], - "translate": [ - 0.1, - 0.1 - ] - }, - "module": "armory.art_experimental.defences.random_affine_pytorch", - "name": "EoTRandomAffinePyTorch", - "type": "Preprocessor" - } - }, - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.37853524, - 0.38404912, - 0.36049628 - ], - "data_stds": [ - 0.18050115, - 0.17266262, - 0.173474 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 64, - 64, - 3 - ], - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121.json b/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121.json deleted file mode 100644 index 139a7095b..000000000 --- a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121.json +++ /dev/null @@ -1,55 +0,0 @@ -{ - "_description": "Resisc45 image classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "use_label": false - }, - "dataset": { - "batch_size": 16, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc45" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.densenet121_resisc45", - "name": "get_art_model", - "weights_file": "densenet121_resisc45_v1.h5", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_cascade.json b/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_cascade.json deleted file mode 100644 index ad8fe9dde..000000000 --- a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_cascade.json +++ /dev/null @@ -1,79 +0,0 @@ -{ - "_description": "Resisc45 image classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "eps": 0.2, - "inner_configs": [ - { - "kwargs": { - "eps": 0.2, - "eps_step": 0.1, - "max_iter": 100, - "num_random_init": 0 - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent" - }, - { - "kwargs": { - "batch_size": 1, - "confidence": 0.9, - "max_iter": 10 - }, - "module": "art.attacks.evasion", - "name": "CarliniLInfMethod" - }, - { - "kwargs": { - "max_iter": 1000 - }, - "module": "art.attacks.evasion", - "name": "BoundaryAttack" - } - ], - "targeted": false - }, - "module": "armory.art_experimental.attacks.cascading_attack", - "name": "CascadingAttack", - "use_label": false - }, - "dataset": { - "batch_size": 16, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc45" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.densenet121_resisc45", - "name": "get_art_model", - "weights_file": "densenet121_resisc45_v1.h5", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_finetune.json b/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_finetune.json deleted file mode 100644 index 2b9ff9a83..000000000 --- a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_finetune.json +++ /dev/null @@ -1,55 +0,0 @@ -{ - "_description": "Resisc45 image classification with pretained weights from imagenet, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "use_label": false - }, - "dataset": { - "batch_size": 16, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc45" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.densenet121_resisc45", - "name": "get_art_model", - "weights_file": "densenet121_imagenet_v1.h5", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_sweep_eps.json b/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_sweep_eps.json deleted file mode 100644 index c8339ce64..000000000 --- a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_sweep_eps.json +++ /dev/null @@ -1,78 +0,0 @@ -{ - "_description": "Resisc45 image classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "sweep_params": { - "kwargs": { - "eps": [ - 0.01, - 0.02, - 0.03, - 0.04, - 0.05, - 0.06, - 0.07, - 0.08 - ], - "eps_step": [ - 0.005, - 0.01, - 0.015, - 0.02, - 0.025, - 0.03, - 0.035, - 0.04 - ] - } - }, - "type": "sweep", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc45" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.densenet121_resisc45", - "name": "get_art_model", - "weights_file": "densenet121_resisc45_v1.h5", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_targeted.json b/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_targeted.json deleted file mode 100644 index 00f8d3aa5..000000000 --- a/docs/scenario_configs/eval1-4/resisc45/resisc45_baseline_densenet121_targeted.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Resisc45 image classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.5, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": true - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "targeted_labels": { - "kwargs": { - "num_classes": 45 - }, - "module": "armory.utils.labels", - "name": "RoundRobinTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 16, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "resisc45" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.densenet121_resisc45", - "name": "get_art_model", - "weights_file": "densenet121_resisc45_v1.h5", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_defended.json b/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_defended.json deleted file mode 100644 index 582871db6..000000000 --- a/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_defended.json +++ /dev/null @@ -1,146 +0,0 @@ -{ - "_description": "Baseline so2sat classification", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.05 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.01, - "max_iter": 300, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 8, - "eval_split": "validation", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "so2sat" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "clip_values": [ - 0.0, - 1.0 - ], - "mins": [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - "quality": 95, - "ranges": [ - 0.46, - 0.48, - 1.52, - 1.11, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - }, - "module": "armory.art_experimental.defences.jpeg_compression_multichannel_image", - "name": "JpegCompressionMultiChannelImage", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.so2sat", - "name": "get_art_model", - "weights_file": "multimodal_baseline_weights.h5", - "wrapper_kwargs": { - "clip_values": [ - [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - [ - 0.24, - 0.22, - 0.79, - 0.36, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - ] - } - }, - "scenario": { - "kwargs": { - "attack_modality": "eo" - }, - "module": "armory.scenarios.multimodal_so2sat_scenario", - "name": "So2SatClassification" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_undefended.json b/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_undefended.json deleted file mode 100644 index bf4f77511..000000000 --- a/docs/scenario_configs/eval1-4/so2sat/so2sat_eo_masked_pgd_undefended.json +++ /dev/null @@ -1,100 +0,0 @@ -{ - "_description": "Baseline so2sat classification", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.05 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.01, - "max_iter": 300, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 8, - "eval_split": "validation", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "so2sat" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.so2sat", - "name": "get_art_model", - "weights_file": "multimodal_baseline_weights.h5", - "wrapper_kwargs": { - "clip_values": [ - [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - [ - 0.24, - 0.22, - 0.79, - 0.36, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - ] - } - }, - "scenario": { - "kwargs": { - "attack_modality": "eo" - }, - "module": "armory.scenarios.multimodal_so2sat_scenario", - "name": "So2SatClassification" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_defended.json b/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_defended.json deleted file mode 100644 index d92110525..000000000 --- a/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_defended.json +++ /dev/null @@ -1,146 +0,0 @@ -{ - "_description": "Baseline so2sat classification", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.05 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 2.0, - "eps_step": 0.01, - "max_iter": 300, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 8, - "eval_split": "validation", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "so2sat" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "clip_values": [ - 0.0, - 1.0 - ], - "mins": [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - "quality": 95, - "ranges": [ - 0.46, - 0.48, - 1.52, - 1.11, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - }, - "module": "armory.art_experimental.defences.jpeg_compression_multichannel_image", - "name": "JpegCompressionMultiChannelImage", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.so2sat", - "name": "get_art_model", - "weights_file": "multimodal_baseline_weights.h5", - "wrapper_kwargs": { - "clip_values": [ - [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - [ - 0.24, - 0.22, - 0.79, - 0.36, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - ] - } - }, - "scenario": { - "kwargs": { - "attack_modality": "sar" - }, - "module": "armory.scenarios.multimodal_so2sat_scenario", - "name": "So2SatClassification" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_undefended.json b/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_undefended.json deleted file mode 100644 index ccdd98223..000000000 --- a/docs/scenario_configs/eval1-4/so2sat/so2sat_sar_masked_pgd_undefended.json +++ /dev/null @@ -1,100 +0,0 @@ -{ - "_description": "Baseline so2sat classification", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.05 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 2.0, - "eps_step": 0.01, - "max_iter": 300, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 8, - "eval_split": "validation", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "so2sat" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.so2sat", - "name": "get_art_model", - "weights_file": "multimodal_baseline_weights.h5", - "wrapper_kwargs": { - "clip_values": [ - [ - -0.22, - -0.26, - -0.73, - -0.75, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0, - 0 - ], - [ - 0.24, - 0.22, - 0.79, - 0.36, - 0.7, - 0.7, - 0.7, - 0.61, - 0.7, - 0.7, - 0.7, - 0.7, - 0.62, - 0.54 - ] - ] - } - }, - "scenario": { - "kwargs": { - "attack_modality": "sar" - }, - "module": "armory.scenarios.multimodal_so2sat_scenario", - "name": "So2SatClassification" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet.json b/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet.json deleted file mode 100644 index 730c9b488..000000000 --- a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet.json +++ /dev/null @@ -1,65 +0,0 @@ -{ - "_description": "Librispeech_dev_clean raw audio classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech_dev_clean" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "fit_batch_size": 16, - "nb_epochs": 20000 - }, - "model_kwargs": { - "predict_mode": "all" - }, - "module": "armory.baseline_models.pytorch.sincnet", - "name": "get_art_model", - "weights_file": "sincnet_librispeech_v1.pth", - "wrapper_kwargs": { - "clip_values": [ - -1.0, - 1.0 - ] - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_classification", - "name": "AudioClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "hkakitani/SincNet", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_snr_pgd.json b/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_snr_pgd.json deleted file mode 100644 index c6c7b32cd..000000000 --- a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_snr_pgd.json +++ /dev/null @@ -1,69 +0,0 @@ -{ - "_description": "Librispeech_dev_clean raw audio classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 10, - "eps_step": 0.5, - "max_iter": 10, - "norm": "snr", - "num_random_init": 0, - "targeted": false - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech_dev_clean" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": [ - "snr", - "snr_db" - ], - "record_metric_per_sample": true, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "fit_batch_size": 16, - "nb_epochs": 20000 - }, - "model_kwargs": { - "predict_mode": "all" - }, - "module": "armory.baseline_models.pytorch.sincnet", - "name": "get_art_model", - "weights_file": "sincnet_librispeech_v1.pth", - "wrapper_kwargs": { - "clip_values": [ - -1.0, - 1.0 - ] - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_classification", - "name": "AudioClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "hkakitani/SincNet", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_targeted.json b/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_targeted.json deleted file mode 100644 index e8c1e06c1..000000000 --- a/docs/scenario_configs/eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_targeted.json +++ /dev/null @@ -1,72 +0,0 @@ -{ - "_description": "Librispeech_dev_clean raw audio classification, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": true - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "targeted_labels": { - "kwargs": { - "num_classes": 40 - }, - "module": "armory.utils.labels", - "name": "RoundRobinTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech_dev_clean" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "fit_batch_size": 16, - "nb_epochs": 20000 - }, - "model_kwargs": { - "predict_mode": "all" - }, - "module": "armory.baseline_models.pytorch.sincnet", - "name": "get_art_model", - "weights_file": "sincnet_librispeech_v1.pth", - "wrapper_kwargs": { - "clip_values": [ - -1.0, - 1.0 - ] - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_classification", - "name": "AudioClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "hkakitani/SincNet", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_finetune.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_finetune.json deleted file mode 100644 index f0842e389..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_finetune.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "UCF101 video classification with finetuning, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "fit_batch_size": 16, - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "kinetics_pretrained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_kinetics_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_pretrained_targeted.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_pretrained_targeted.json deleted file mode 100644 index 3b3fa80b0..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_baseline_pretrained_targeted.json +++ /dev/null @@ -1,68 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": true - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod", - "targeted_labels": { - "kwargs": { - "num_classes": 101 - }, - "module": "armory.utils.labels", - "name": "RoundRobinTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_defended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_defended.json deleted file mode 100644 index d825cfb40..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_defended.json +++ /dev/null @@ -1,77 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "beta_0": 1.0, - "beta_1": 0.5, - "beta_2": 0.5, - "eps_step": 0.02, - "loss_margin": 0.05, - "max_iter": 100, - "start_frame_index": 0, - "targeted": false - }, - "module": "art.attacks.evasion.over_the_air_flickering.over_the_air_flickering_pytorch", - "name": "OverTheAirFlickeringPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "constant_rate_factor": 28, - "verbose": false, - "video_format": "avi" - }, - "module": "armory.art_experimental.defences.video_compression_normalized", - "name": "VideoCompressionNormalizedPyTorch", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": [ - "l0" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_undefended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_undefended.json deleted file mode 100644 index b1ad76f61..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_flicker_undefended.json +++ /dev/null @@ -1,65 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "beta_0": 1.0, - "beta_1": 0.5, - "beta_2": 0.5, - "eps_step": 0.02, - "loss_margin": 0.05, - "max_iter": 100, - "start_frame_index": 0, - "targeted": false - }, - "module": "art.attacks.evasion.over_the_air_flickering.over_the_air_flickering_pytorch", - "name": "OverTheAirFlickeringPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": [ - "l0" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_defended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_defended.json deleted file mode 100644 index 362b7eb79..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_defended.json +++ /dev/null @@ -1,86 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "frame_index": 1, - "inner_config": { - "kwargs": { - "batch_size": 1, - "eps": 0.015, - "eps_step": 0.001, - "max_iter": 100, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent" - }, - "method": "iterative_saliency", - "verbose": false - }, - "module": "armory.art_experimental.attacks.frame", - "name": "get_frame_saliency", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "constant_rate_factor": 28, - "verbose": false, - "video_format": "avi" - }, - "module": "armory.art_experimental.defences.video_compression_normalized", - "name": "VideoCompressionNormalized", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": [ - "l0", - "linf" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_undefended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_undefended.json deleted file mode 100644 index 3b7a6408a..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_frame_saliency_undefended.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "frame_index": 1, - "inner_config": { - "kwargs": { - "batch_size": 1, - "eps": 0.015, - "eps_step": 0.001, - "max_iter": 100, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent" - }, - "method": "iterative_saliency", - "verbose": false - }, - "module": "armory.art_experimental.attacks.frame", - "name": "get_frame_saliency", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": [ - "l0", - "linf" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_defended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_defended.json deleted file mode 100644 index b8a4aba72..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_defended.json +++ /dev/null @@ -1,83 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.1, - "video_input": true, - "xmin": 0, - "ymin": 0 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.02, - "max_iter": 100, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "constant_rate_factor": 28, - "verbose": false, - "video_format": "avi" - }, - "module": "armory.art_experimental.defences.video_compression_normalized", - "name": "VideoCompressionNormalized", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": [ - "l0" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_undefended.json b/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_undefended.json deleted file mode 100644 index 640ea490c..000000000 --- a/docs/scenario_configs/eval1-4/ucf101/ucf101_pretrained_masked_pgd_undefended.json +++ /dev/null @@ -1,71 +0,0 @@ -{ - "_description": "UCF101 video classification from pretrained, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_ratio": 0.1, - "video_input": true, - "xmin": 0, - "ymin": 0 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.02, - "max_iter": 100, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "max_frames": 512, - "module": "armory.data.datasets", - "name": "ucf101" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": [ - "l0" - ], - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy", - "top_5_categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 10 - }, - "model_kwargs": { - "model_status": "ucf101_trained" - }, - "module": "armory.baseline_models.pytorch.ucf101_mars", - "name": "get_art_model", - "weights_file": "mars_ucf101_v1.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.video_ucf101_scenario", - "name": "Ucf101" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "yusong-tan/MARS", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_defended.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_defended.json deleted file mode 100644 index 1bc944c42..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_defended.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_height": 50, - "patch_width": 50 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.004, - "max_iter": 500, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_undefended.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_undefended.json deleted file mode 100644 index a57643e11..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_masked_pgd_undefended.json +++ /dev/null @@ -1,61 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_height": 50, - "patch_width": 50 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.004, - "max_iter": 500, - "num_random_init": 0, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_defended.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_defended.json deleted file mode 100644 index 9aa3e88c3..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_defended.json +++ /dev/null @@ -1,76 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "brightness_range": [ - 0.8, - 1.0 - ], - "learning_rate": 0.01, - "max_iter": 200, - "patch_shape": [ - 50, - 50, - 3 - ], - "sample_size": 10, - "verbose": false - }, - "module": "armory.art_experimental.attacks.robust_dpatch", - "name": "RobustDPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_undefended.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_undefended.json deleted file mode 100644 index 995767ffc..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_robust_dpatch_undefended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "brightness_range": [ - 0.8, - 1.0 - ], - "learning_rate": 0.01, - "max_iter": 200, - "patch_shape": [ - 50, - 50, - 3 - ], - "sample_size": 10, - "verbose": false - }, - "module": "armory.art_experimental.attacks.robust_dpatch", - "name": "RobustDPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_sweep_patch_size.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_sweep_patch_size.json deleted file mode 100644 index 0efb2768a..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_sweep_patch_size.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "xmin": 0, - "ymin": 0 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.01, - "max_iter": 100, - "num_random_init": 0, - "random_eps": false, - "targeted": true, - "verbose": true - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "sweep_params": { - "generate_kwargs": { - "patch_height": [ - 10, - 20, - 30, - 40, - 50, - 60, - 70, - 80, - 90, - 100, - 110 - ], - "patch_width": [ - 10, - 20, - 30, - 40, - 50, - 60, - 70, - 80, - 90, - 100, - 110 - ] - }, - "kwargs": {}, - "metric": { - "module": "armory.metrics.task", - "name": "object_detection_mAP", - "threshold": 0.1 - } - }, - "targeted_labels": { - "kwargs": { - "value": 2 - }, - "module": "armory.utils.labels", - "name": "ObjectDetectionFixedLabelTargeter" - }, - "type": "sweep", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": true, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval1-4/xview/xview_frcnn_targeted.json b/docs/scenario_configs/eval1-4/xview/xview_frcnn_targeted.json deleted file mode 100644 index 548649dbb..000000000 --- a/docs/scenario_configs/eval1-4/xview/xview_frcnn_targeted.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "XView object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "generate_kwargs": { - "patch_height": 50, - "patch_width": 50, - "xmin": 0, - "ymin": 0 - }, - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 1.0, - "eps_step": 0.01, - "max_iter": 200, - "num_random_init": 0, - "random_eps": false, - "targeted": true, - "verbose": true - }, - "module": "armory.art_experimental.attacks.pgd_patch", - "name": "PGDPatch", - "targeted_labels": { - "kwargs": { - "value": 2 - }, - "module": "armory.utils.labels", - "name": "ObjectDetectionFixedLabelTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "xview" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "object_detection_AP_per_class" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.xview_frcnn", - "name": "get_art_model", - "weights_file": "xview_model_state_dict_epoch_99_loss_0p67", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.object_detection", - "name": "ObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/defended_entailment.json b/docs/scenario_configs/eval5/asr_librispeech/defended_entailment.json deleted file mode 100644 index 5727d7654..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/defended_entailment.json +++ /dev/null @@ -1,97 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.05, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "dtype": "str", - "import_from": "armory.attacks.librispeech_target_labels", - "values": "entailment_100" - }, - "module": "armory.utils.labels", - "name": "ManualTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3Compression", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "entailment", - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": [ - "SeanNaren/deepspeech.pytorch@V3.0" - ], - "gpus": "all", - "local_repo_path": null, - "num_eval_batches": 100, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/defended_targeted_snr_pgd.json b/docs/scenario_configs/eval5/asr_librispeech/defended_targeted_snr_pgd.json deleted file mode 100644 index c9ff3fdb2..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/defended_targeted_snr_pgd.json +++ /dev/null @@ -1,92 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.5, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "import_from": "armory.attacks.librispeech_target_labels", - "transcripts": "matched_length" - }, - "module": "armory.utils.labels", - "name": "MatchedTranscriptLengthTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3Compression", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/defended_untargeted_snr_pgd.json b/docs/scenario_configs/eval5/asr_librispeech/defended_untargeted_snr_pgd.json deleted file mode 100644 index 4c128b261..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/defended_untargeted_snr_pgd.json +++ /dev/null @@ -1,84 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.5, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": false - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "sample_rate": 16000, - "verbose": false - }, - "module": "art.defences.preprocessor", - "name": "Mp3Compression", - "type": "Preprocessor" - }, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/entailment.json b/docs/scenario_configs/eval5/asr_librispeech/entailment.json deleted file mode 100644 index 21f5ff3e1..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/entailment.json +++ /dev/null @@ -1,86 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.05, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "dtype": "str", - "import_from": "armory.attacks.librispeech_target_labels", - "values": "entailment_100" - }, - "module": "armory.utils.labels", - "name": "ManualTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "snr_db", - "record_metric_per_sample": true, - "task": [ - "entailment", - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": [ - "SeanNaren/deepspeech.pytorch@V3.0" - ], - "gpus": "all", - "local_repo_path": null, - "num_eval_batches": 100, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/targeted_snr_pgd.json b/docs/scenario_configs/eval5/asr_librispeech/targeted_snr_pgd.json deleted file mode 100644 index f650a46eb..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/targeted_snr_pgd.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.5, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": true - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": true, - "targeted_labels": { - "kwargs": { - "import_from": "armory.attacks.librispeech_target_labels", - "transcripts": "matched_length" - }, - "module": "armory.utils.labels", - "name": "MatchedTranscriptLengthTargeter" - }, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/asr_librispeech/untargeted_snr_pgd.json b/docs/scenario_configs/eval5/asr_librispeech/untargeted_snr_pgd.json deleted file mode 100644 index 58a8c1af8..000000000 --- a/docs/scenario_configs/eval5/asr_librispeech/untargeted_snr_pgd.json +++ /dev/null @@ -1,73 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.5, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": false - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.deep_speech", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": { - "clip_values": [ - -1, - 1 - ], - "pretrained_model": "librispeech" - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch-deepspeech", - "external_github_repo": "SeanNaren/deepspeech.pytorch@V3.0", - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_adversarialpatch_undefended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_adversarialpatch_undefended.json deleted file mode 100644 index f979ed301..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_adversarialpatch_undefended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.003, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_defended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_defended.json deleted file mode 100644 index e357819e4..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_defended.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.002, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_undefended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_undefended.json deleted file mode 100644 index 69edd6dc5..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_dpatch_undefended.json +++ /dev/null @@ -1,61 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.002, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json deleted file mode 100644 index 22677a106..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json +++ /dev/null @@ -1,65 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 3, - "learning_rate": 0.003, - "learning_rate_depth": 0.0001, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn_robust_fusion", - "name": "get_art_model_mm_robust", - "weights_file": "carla_multimodal_robust_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json deleted file mode 100644 index 14da4a6a6..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json +++ /dev/null @@ -1,65 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 3, - "learning_rate": 0.003, - "learning_rate_depth": 0.0001, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn", - "name": "get_art_model_mm", - "weights_file": "carla_multimodal_naive_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_defended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_defended.json deleted file mode 100644 index 67bff76ba..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_defended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 3, - "learning_rate": 0.002, - "learning_rate_depth": 0.0001, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn_robust_fusion", - "name": "get_art_model_mm_robust", - "weights_file": "carla_multimodal_robust_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_undefended.json b/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_undefended.json deleted file mode 100644 index b855c7675..000000000 --- a/docs/scenario_configs/eval5/carla_object_detection/carla_obj_det_multimodal_dpatch_undefended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 3, - "learning_rate": 0.002, - "learning_rate_depth": 0.0001, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn", - "name": "get_art_model_mm", - "weights_file": "carla_multimodal_naive_weights_eval5.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_defended.json b/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_defended.json deleted file mode 100644 index c4f56479f..000000000 --- a/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_defended.json +++ /dev/null @@ -1,67 +0,0 @@ -{ - "_description": "CARLA video tracking, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "max_iter": 100, - "step_size": 0.02, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_adversarial_texture", - "name": "AdversarialPhysicalTexture", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "carla_video_tracking_dev" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "channels_first": false, - "constant_rate_factor": 28, - "verbose": false, - "video_format": "avi" - }, - "module": "armory.art_experimental.defences.video_compression_normalized", - "name": "VideoCompressionNormalizedPyTorch", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "video_tracking_mean_iou", - "video_tracking_mean_success_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_goturn", - "name": "get_art_model", - "weights_file": "pytorch_goturn.pth.tar", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_video_tracking", - "name": "CarlaVideoTracking" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "amoudgl/pygoturn", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_undefended.json b/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_undefended.json deleted file mode 100644 index 3dd6dc8a0..000000000 --- a/docs/scenario_configs/eval5/carla_video_tracking/carla_video_tracking_goturn_advtextures_undefended.json +++ /dev/null @@ -1,55 +0,0 @@ -{ - "_description": "CARLA video tracking, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "max_iter": 100, - "step_size": 0.02, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_adversarial_texture", - "name": "AdversarialPhysicalTexture", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "carla_video_tracking_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "video_tracking_mean_iou", - "video_tracking_mean_success_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_goturn", - "name": "get_art_model", - "weights_file": "pytorch_goturn.pth.tar", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_video_tracking", - "name": "CarlaVideoTracking" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "amoudgl/pygoturn", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_activation_defense.json deleted file mode 100644 index a50a7a395..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_activation_defense.json +++ /dev/null @@ -1,97 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "copyright.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 0.18, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_perfect_filter.json deleted file mode 100644 index 443cbf4dc..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_perfect_filter.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "copyright.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 0.18, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_random_filter.json deleted file mode 100644 index ce5bd993b..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_random_filter.json +++ /dev/null @@ -1,94 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "copyright.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 0.18, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_spectral_signature_defense.json deleted file mode 100644 index f25b25c27..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_spectral_signature_defense.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "copyright.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 0.18, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_undefended.json deleted file mode 100644 index 7f578aaab..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/copyright/cifar10_dlbd_copyright_undefended.json +++ /dev/null @@ -1,86 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "copyright.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 0.18, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_activation_defense.json deleted file mode 100644 index fdb2d38e8..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_activation_defense.json +++ /dev/null @@ -1,97 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_perfect_filter.json deleted file mode 100644 index ed6e53fa4..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_perfect_filter.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_random_filter.json deleted file mode 100644 index 3bcff8ede..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_random_filter.json +++ /dev/null @@ -1,94 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_spectral_signature_defense.json deleted file mode 100644 index 509b42419..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_spectral_signature_defense.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_undefended.json deleted file mode 100644 index 925e51188..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/dlbd/watermark/cifar10_dlbd_watermark_undefended.json +++ /dev/null @@ -1,86 +0,0 @@ -{ - "_description": "CIFAR10 dirty label backdoor, watermark trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_activation_defense.json deleted file mode 100644 index 334ea571f..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_activation_defense.json +++ /dev/null @@ -1,131 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_perfect_filter.json deleted file mode 100644 index ac8245dd6..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_perfect_filter.json +++ /dev/null @@ -1,127 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_random_filter.json deleted file mode 100644 index b7cc9fcca..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_random_filter.json +++ /dev/null @@ -1,128 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_spectral_signature_defense.json deleted file mode 100644 index c3b2f4908..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_spectral_signature_defense.json +++ /dev/null @@ -1,127 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_undefended.json deleted file mode 100644 index cacd8e609..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/cifar10/witches_brew/cifar10_witches_brew_undefended.json +++ /dev/null @@ -1,120 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_activation_defense.json deleted file mode 100644 index e9767799e..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_activation_defense.json +++ /dev/null @@ -1,85 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, bullet holes trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_perfect_filter.json deleted file mode 100644 index e5ef2ce72..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_perfect_filter.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, bullet holes trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_random_filter.json deleted file mode 100644 index 42a999aae..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_random_filter.json +++ /dev/null @@ -1,82 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, bullet holes trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_spectral_signature_defense.json deleted file mode 100644 index 9d7cc98f7..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_spectral_signature_defense.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, bullet holes trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_undefended.json deleted file mode 100644 index 4c5fea615..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/bullet_holes/gtsrb_clbd_bullet_holes_undefended.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, bullet holes trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_activation_defense.json deleted file mode 100644 index f22a3a5d1..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_activation_defense.json +++ /dev/null @@ -1,85 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, peace sign trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_perfect_filter.json deleted file mode 100644 index f250e8f33..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_perfect_filter.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, peace sign trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_random_filter.json deleted file mode 100644 index 3f7b91029..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_random_filter.json +++ /dev/null @@ -1,82 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, peace sign trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_spectral_signature_defense.json deleted file mode 100644 index 7e408ffe2..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_spectral_signature_defense.json +++ /dev/null @@ -1,81 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, peace sign trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_undefended.json deleted file mode 100644 index 43f291367..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/clbd/peace_sign/gtsrb_clbd_peace_sign_undefended.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "GTSRB clean label backdoor, peace sign trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "eps": 0.03, - "eps_step": 0.001, - "max_iter": 100, - "n_classes": 43, - "norm": "inf", - "num_random_init": 0, - "pp_poison": 0.2, - "target": 2 - }, - "module": "armory.art_experimental.attacks.poison_loader_clbd", - "name": "poison_loader_clbd", - "type": "clbd", - "use_adversarial_trainer": false - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poisoning_clbd", - "name": "Poison_CLBD" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_activation_defense.json deleted file mode 100644 index f121d0cdf..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_activation_defense.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, bullet holes trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_perfect_filter.json deleted file mode 100644 index c11204312..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_perfect_filter.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, bullet holes trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_random_filter.json deleted file mode 100644 index 8d8db0c6b..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_random_filter.json +++ /dev/null @@ -1,71 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, bullet holes trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_spectral_signature_defense.json deleted file mode 100644 index 1c9ca11ea..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_spectral_signature_defense.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, bullet holes trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_undefended.json deleted file mode 100644 index a0b6b8bc2..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/bullet_holes/gtsrb_dlbd_bullet_holes_undefended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, bullet holes trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "bullet_holes.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_activation_defense.json deleted file mode 100644 index cc72f0107..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_activation_defense.json +++ /dev/null @@ -1,74 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, peace sign trigger, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_perfect_filter.json deleted file mode 100644 index d7771c848..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_perfect_filter.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, peace sign trigger, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_random_filter.json deleted file mode 100644 index 64738770e..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_random_filter.json +++ /dev/null @@ -1,71 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, peace sign trigger, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_spectral_signature_defense.json deleted file mode 100644 index d0a6e77f2..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_spectral_signature_defense.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, peace sign trigger, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_undefended.json deleted file mode 100644 index 4c1436ba5..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/dlbd/peace_sign/gtsrb_dlbd_peace_sign_undefended.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "_description": "GTSRB dirty label backdoor, peace sign trigger, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "peace.png", - "blend": 0.6, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 16, - 16 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_activation_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_activation_defense.json deleted file mode 100644 index fdd93c243..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_activation_defense.json +++ /dev/null @@ -1,87 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack, activation defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_perfect_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_perfect_filter.json deleted file mode 100644 index 964293649..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_perfect_filter.json +++ /dev/null @@ -1,83 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack, perfect filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_random_filter.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_random_filter.json deleted file mode 100644 index bc0971933..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_random_filter.json +++ /dev/null @@ -1,84 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack, random filter", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_spectral_signature_defense.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_spectral_signature_defense.json deleted file mode 100644 index 367428039..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_spectral_signature_defense.json +++ /dev/null @@ -1,83 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack, spectral signature defense", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_undefended.json b/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_undefended.json deleted file mode 100644 index 027a85fa6..000000000 --- a/docs/scenario_configs/eval5/poisoning/baseline_defenses/gtsrb/witches_brew/gtsrb_witches_brew_undefended.json +++ /dev/null @@ -1,76 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack, undefended", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/cifar10_poison_dlbd.json b/docs/scenario_configs/eval5/poisoning/cifar10_poison_dlbd.json deleted file mode 100644 index c0ade563c..000000000 --- a/docs/scenario_configs/eval5/poisoning/cifar10_poison_dlbd.json +++ /dev/null @@ -1,97 +0,0 @@ -{ - "_description": "CIFAR10 DLBD poison image classification", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 2, - "train_epochs": 200, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_path": "watermarking.png", - "base_img_size_x": 32, - "base_img_size_y": 32, - "blend": 1.0, - "channels_first": false, - "mode": "RGB", - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "image", - "size": [ - 32, - 32 - ] - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/cifar10_witches_brew.json b/docs/scenario_configs/eval5/poisoning/cifar10_witches_brew.json deleted file mode 100644 index ab4e7cd09..000000000 --- a/docs/scenario_configs/eval5/poisoning/cifar10_witches_brew.json +++ /dev/null @@ -1,131 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, witches' brew attack", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": [ - 0, - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9 - ], - "split_id": 0, - "target_class": [ - 1, - 2, - 3, - 4, - 5, - 6, - 7, - 8, - 9, - 0 - ], - "train_epochs": 100, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 750, - "data_filepath": null, - "epsilon": 0.125, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 94, - 156, - 219, - 250, - 350 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.001, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_keras.json b/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_keras.json deleted file mode 100644 index c7720d8d8..000000000 --- a/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_keras.json +++ /dev/null @@ -1,66 +0,0 @@ -{ - "_description": "GTSRB poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "pattern" - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_pytorch.json b/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_pytorch.json deleted file mode 100644 index e37b2f619..000000000 --- a/docs/scenario_configs/eval5/poisoning/gtsrb_dlbd_baseline_pytorch.json +++ /dev/null @@ -1,66 +0,0 @@ -{ - "_description": "GTSRB poison image classification, contributed by MITRE Corporation", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "poison_module": "art.attacks.poisoning.perturbations", - "poison_type": "pattern" - }, - "module": "armory.art_experimental.attacks.poison_loader_dlbd", - "name": "poison_loader_dlbd" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval5/poisoning/gtsrb_witches_brew.json b/docs/scenario_configs/eval5/poisoning/gtsrb_witches_brew.json deleted file mode 100644 index efd02102a..000000000 --- a/docs/scenario_configs/eval5/poisoning/gtsrb_witches_brew.json +++ /dev/null @@ -1,87 +0,0 @@ -{ - "_description": "GTSRB poison image classification, witches' brew attack", - "adhoc": { - "compute_fairness_metrics": true, - "experiment_id": 0, - "explanatory_model": "gtsrb_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 1, - "split_id": 0, - "target_class": 2, - "train_epochs": 30, - "trigger_index": null, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "data_filepath": "gtsrb_gradient_matching_precomputed.npz", - "epsilon": 0.1, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "verbose": 1 - }, - "module": "armory.art_experimental.attacks.gradient_matching", - "name": "GradientMatchingWrapper" - }, - "dataset": { - "batch_size": 512, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "german_traffic_sign" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.micronnet_gtsrb", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_witches_brew", - "name": "WitchesBrewScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/asr_librispeech/hubert_untargeted_snr_pgd.json b/docs/scenario_configs/eval6/asr_librispeech/hubert_untargeted_snr_pgd.json deleted file mode 100644 index bba2df86c..000000000 --- a/docs/scenario_configs/eval6/asr_librispeech/hubert_untargeted_snr_pgd.json +++ /dev/null @@ -1,67 +0,0 @@ -{ - "_description": "Baseline DeepSpeech ASR on LibriSpeech, contributed by MITRE Corporation", - "adhoc": { - "skip_adversarial": false - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 20, - "eps_step": 0.5, - "max_iter": 500, - "norm": "snr", - "num_random_init": 0, - "targeted": false - }, - "module": "armory.art_experimental.attacks.snr_pgd", - "name": "SNR_PGD_Numpy", - "targeted": false, - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "test_clean", - "framework": "numpy", - "module": "armory.data.datasets", - "name": "librispeech", - "train_split": "train_clean100" - }, - "defense": null, - "metric": { - "means": false, - "perturbation": "linf", - "record_metric_per_sample": true, - "task": [ - "word_error_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": { - "nb_epochs": 20000 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.hubert_asr_large", - "name": "get_art_model", - "predict_kwargs": { - "transcription_output": true - }, - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.audio_asr", - "name": "AutomaticSpeechRecognition" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "local_repo_path": null, - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_mot/carla_mot_adversarialpatch_undefended.json b/docs/scenario_configs/eval6/carla_mot/carla_mot_adversarialpatch_undefended.json deleted file mode 100644 index 5f15432f0..000000000 --- a/docs/scenario_configs/eval6/carla_mot/carla_mot_adversarialpatch_undefended.json +++ /dev/null @@ -1,82 +0,0 @@ -{ - "_description": "CARLA single modality multi-object tracking, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_frame_size": 2, - "coco_format": true, - "learning_rate": 0.02, - "max_iter": 100, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_mot_adversarial_patch", - "name": "CARLAMOTAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "coco_format": true, - "eval_split": "dev", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "carla_multi_object_tracking_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "hota", - "deta", - "assa" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 2 - }, - "module": "armory.baseline_models.pytorch.carla_mot_frcnn_byte", - "name": "get_art_model", - "weights_file": "carla_mot_weights_eval6.pt", - "wrapper_kwargs": { - "BYTE_kwargs": { - "frame_rate": 30, - "match_thresh": 0.95, - "track_buffer": 60, - "track_thresh": 0.2 - }, - "coco_format": true, - "conf_thresh": 0.0, - "nms_thresh": 0.9, - "tracked_classes": [ - "pedestrian" - ] - } - }, - "scenario": { - "kwargs": { - "coco_format": true, - "tracked_classes": [ - "pedestrian" - ] - }, - "module": "armory.scenarios.carla_mot", - "name": "CarlaMOT" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": [ - "JonathonLuiten/TrackEval" - ], - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_defended.json b/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_defended.json deleted file mode 100644 index 1490f7d69..000000000 --- a/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_defended.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "_description": "CARLA single modality multi-object tracking, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_frame_size": 2, - "learning_rate": 0.002, - "max_iter": 1000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_mot_patch", - "name": "CARLAMOTDapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "coco_format": true, - "eval_split": "dev", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "carla_multi_object_tracking_dev" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "hota", - "deta", - "assa" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 2 - }, - "module": "armory.baseline_models.pytorch.carla_mot_frcnn_byte", - "name": "get_art_model", - "weights_file": "carla_mot_weights_eval6.pt", - "wrapper_kwargs": { - "BYTE_kwargs": { - "frame_rate": 30, - "match_thresh": 0.95, - "track_buffer": 60, - "track_thresh": 0.2 - }, - "coco_format": true, - "conf_thresh": 0.0, - "nms_thresh": 0.9, - "tracked_classes": [ - "pedestrian" - ] - } - }, - "scenario": { - "kwargs": { - "coco_format": true, - "tracked_classes": [ - "pedestrian" - ] - }, - "module": "armory.scenarios.carla_mot", - "name": "CarlaMOT" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": [ - "JonathonLuiten/TrackEval", - "colour-science/colour@v0.3.16" - ], - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_undefended.json b/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_undefended.json deleted file mode 100644 index df80ca8a0..000000000 --- a/docs/scenario_configs/eval6/carla_mot/carla_mot_dpatch_undefended.json +++ /dev/null @@ -1,80 +0,0 @@ -{ - "_description": "CARLA single modality multi-object tracking, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_frame_size": 2, - "learning_rate": 0.002, - "max_iter": 1000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_mot_patch", - "name": "CARLAMOTDapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "coco_format": true, - "eval_split": "dev", - "framework": "numpy", - "module": "armory.data.adversarial_datasets", - "name": "carla_multi_object_tracking_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "hota", - "deta", - "assa" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 2 - }, - "module": "armory.baseline_models.pytorch.carla_mot_frcnn_byte", - "name": "get_art_model", - "weights_file": "carla_mot_weights_eval6.pt", - "wrapper_kwargs": { - "BYTE_kwargs": { - "frame_rate": 30, - "match_thresh": 0.95, - "track_buffer": 60, - "track_thresh": 0.2 - }, - "coco_format": true, - "conf_thresh": 0.0, - "nms_thresh": 0.9, - "tracked_classes": [ - "pedestrian" - ] - } - }, - "scenario": { - "kwargs": { - "coco_format": true, - "tracked_classes": [ - "pedestrian" - ] - }, - "module": "armory.scenarios.carla_mot", - "name": "CarlaMOT" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": [ - "JonathonLuiten/TrackEval", - "colour-science/colour@v0.3.16" - ], - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_adversarialpatch_undefended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_adversarialpatch_undefended.json deleted file mode 100644 index db788f0e6..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_adversarialpatch_undefended.json +++ /dev/null @@ -1,64 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.003, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 3 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_defended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_defended.json deleted file mode 100644 index 225976d8c..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_defended.json +++ /dev/null @@ -1,75 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.002, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 3 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_undefended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_undefended.json deleted file mode 100644 index ea91f7ec1..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_dpatch_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.002, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 3 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json deleted file mode 100644 index a006a3f67..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_defended.json +++ /dev/null @@ -1,64 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 0.03, - "learning_rate": 0.003, - "learning_rate_depth": 0.0001, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn_robust_fusion", - "name": "get_art_model_mm_robust", - "weights_file": "carla_multimodal_robust_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json deleted file mode 100644 index e88c6bfe1..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_adversarialpatch_undefended.json +++ /dev/null @@ -1,64 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 0.03, - "learning_rate": 0.003, - "learning_rate_depth": 0.0001, - "max_iter": 1000, - "optimizer": "pgd", - "targeted": false, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_adversarial_patch", - "name": "CARLAAdversarialPatchPyTorch", - "use_label": true - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn", - "name": "get_art_model_mm", - "weights_file": "carla_multimodal_naive_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_defended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_defended.json deleted file mode 100644 index 2c0224124..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_defended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 0.03, - "learning_rate": 0.002, - "learning_rate_depth": 0.0001, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn_robust_fusion", - "name": "get_art_model_mm_robust", - "weights_file": "carla_multimodal_robust_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_undefended.json b/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_undefended.json deleted file mode 100644 index 7f9e54d7f..000000000 --- a/docs/scenario_configs/eval6/carla_overhead_object_detection/carla_obj_det_multimodal_dpatch_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "CARLA multimodality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "depth_delta_meters": 0.03, - "learning_rate": 0.002, - "learning_rate_depth": 0.0001, - "max_iter": 2000, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "modality": "both", - "module": "armory.data.adversarial_datasets", - "name": "carla_over_obj_det_dev" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate", - "object_detection_mAP_tide" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.carla_multimodality_object_detection_frcnn", - "name": "get_art_model_mm", - "weights_file": "carla_multimodal_naive_weights_eval6.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour@v0.3.16", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p00_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p00_undefended.json deleted file mode 100644 index 03aa75c66..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p00_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0, - "poison_dataset": false, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p01_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p01_undefended.json deleted file mode 100644 index 06d344593..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p01_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p05_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p05_undefended.json deleted file mode 100644 index 2cbaaaaa2..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p05_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0.05, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p10_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p10_undefended.json deleted file mode 100644 index 701f86798..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p10_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p20_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p20_undefended.json deleted file mode 100644 index fa91de51b..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p20_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0.2, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p30_undefended.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p30_undefended.json deleted file mode 100644 index e29bb9faf..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/audio_p30_undefended.json +++ /dev/null @@ -1,62 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "speech_commands_explanatory_model", - "fraction_poisoned": 0.3, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_activation_defense.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_activation_defense.json deleted file mode 100644 index 51dea568e..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_activation_defense.json +++ /dev/null @@ -1,73 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, activation defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": null, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_dpinstahide.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_dpinstahide.json deleted file mode 100644 index b35b7a779..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_dpinstahide.json +++ /dev/null @@ -1,84 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, DP Instahide defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": null, - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": { - "kwargs": { - "augmentations": { - "kwargs": { - "apply_fit": true, - "apply_predict": false, - "num_classes": 12, - "num_mix": 2 - }, - "name": "Mixup" - }, - "clip_values": [ - 0, - 1 - ], - "noise": "laplacian", - "scale": 0.015 - }, - "module": "art.defences.trainer", - "name": "DPInstaHideTrainer", - "type": "Trainer" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_perfect_filter.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_perfect_filter.json deleted file mode 100644 index 17dce65af..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_perfect_filter.json +++ /dev/null @@ -1,69 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, perfect filter", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": null, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_random_filter.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_random_filter.json deleted file mode 100644 index 5e61eeff4..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_random_filter.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, random filter", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": null, - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_spectral_signature_defense.json b/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_spectral_signature_defense.json deleted file mode 100644 index 06a6f08a5..000000000 --- a/docs/scenario_configs/eval6/poisoning/audio_dlbd/baseline_defenses/audio_p10_spectral_signature_defense.json +++ /dev/null @@ -1,69 +0,0 @@ -{ - "_description": "Speech Commands DLBD poison audio classification, spectral signatures defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": null, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 11, - "split_id": 0, - "target_class": 2, - "train_epochs": 20, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "backdoor_kwargs": { - "backdoor_path": "clapping.wav", - "duration": 1, - "random": false, - "sampling_rate": 16000, - "scale": 0.1, - "shift": 0 - } - }, - "module": "armory.art_experimental.attacks.poison_loader_audio", - "name": "poison_loader_audio" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "speech_commands", - "pad_data": true - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.tf_graph.audio_resnet50", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.poison", - "name": "Poison" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_activation_defense.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_activation_defense.json deleted file mode 100644 index fd87cebdb..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_activation_defense.json +++ /dev/null @@ -1,116 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, activation defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "cluster_analysis": "smaller", - "clustering_method": "KMeans", - "nb_clusters": 2, - "nb_dims": 43, - "reduce": "PCA" - }, - "module": "art.defences.detector.poison.activation_defence", - "name": "ActivationDefence", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_dpinstahide.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_dpinstahide.json deleted file mode 100644 index 8a4193c69..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_dpinstahide.json +++ /dev/null @@ -1,127 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, DP Instahide defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "augmentations": { - "kwargs": { - "apply_fit": true, - "apply_predict": false, - "num_classes": 10, - "num_mix": 2 - }, - "name": "Mixup" - }, - "clip_values": [ - 0, - 1 - ], - "noise": "laplacian", - "scale": 0.03 - }, - "module": "art.defences.trainer", - "name": "DPInstaHideTrainer", - "type": "Trainer" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/pytorch", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_perfect_filter.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_perfect_filter.json deleted file mode 100644 index 661a54d9a..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_perfect_filter.json +++ /dev/null @@ -1,112 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, perfect filter", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "perfect_filter": true - }, - "module": "null", - "name": "null", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_random_filter.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_random_filter.json deleted file mode 100644 index 69ebd7138..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_random_filter.json +++ /dev/null @@ -1,113 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, random filter", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fit_defense_classifier_outside_defense": false, - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "armory.art_experimental.poison_detection.random_filter", - "name": "RandomFilterBaselineDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_spectral_signatures_defense.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_spectral_signatures_defense.json deleted file mode 100644 index 89e995696..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/baseline_defenses/cifar10_sleeper_agent_p10_spectral_signatures_defense.json +++ /dev/null @@ -1,112 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, spectral signatures defense", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": true - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": { - "kwargs": { - "expected_pp_poison": 0.3 - }, - "module": "art.defences.detector.poison.spectral_signature_defense", - "name": "SpectralSignatureDefense", - "type": "PoisonFilteringDefence" - }, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p00_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p00_undefended.json deleted file mode 100644 index 105705587..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p00_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0, - "poison_dataset": false, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p01_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p01_undefended.json deleted file mode 100644 index c6e6b5aa1..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p01_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.01, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p05_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p05_undefended.json deleted file mode 100644 index c7cede80f..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p05_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.05, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p10_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p10_undefended.json deleted file mode 100644 index 815c4f7a3..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p10_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.1, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p20_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p20_undefended.json deleted file mode 100644 index 33ccab3a2..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p20_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.2, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p30_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p30_undefended.json deleted file mode 100644 index dd2c23ab2..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p30_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.3, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p50_undefended.json b/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p50_undefended.json deleted file mode 100644 index f5268d749..000000000 --- a/docs/scenario_configs/eval6/poisoning/sleeper_agent/cifar10_sleeper_agent_p50_undefended.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "_description": "CIFAR10 poison image classification, sleeper agent attack, undefended", - "adhoc": { - "compute_fairness_metrics": false, - "experiment_id": 0, - "explanatory_model": "cifar10_explanatory_model", - "fraction_poisoned": 0.5, - "poison_dataset": true, - "source_class": 0, - "split_id": 0, - "target_class": 1, - "train_epochs": 80, - "use_poison_filtering_defense": false - }, - "attack": { - "knowledge": "black", - "kwargs": { - "batch_size": 500, - "device_name": "cuda", - "epsilon": 0.0627, - "k_trigger": 1000, - "learning_rate_schedule": [ - [ - 0.1, - 0.01, - 0.001, - 0.0001, - 1e-05 - ], - [ - 250, - 350, - 400, - 430, - 460 - ] - ], - "max_epochs": 500, - "max_trials": 1, - "model_retrain": true, - "model_retraining_epoch": 80, - "patch": "trigger_10.png", - "patch_size": 8, - "patching_strategy": "random", - "retraining_factor": 4, - "selection_strategy": "max-norm", - "verbose": 1 - }, - "module": "art.attacks.poisoning.sleeper_agent_attack", - "name": "SleeperAgentAttack" - }, - "dataset": { - "batch_size": 128, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": { - "data_means": [ - 0.4914, - 0.4822, - 0.4465 - ], - "data_stds": [ - 0.247, - 0.2435, - 0.2616 - ], - "num_classes": 10, - "pretrained": false - }, - "module": "armory.baseline_models.pytorch.resnet18", - "name": "get_art_model_cifar_sleeper_agent", - "weights_file": null, - "wrapper_kwargs": { - "input_shape": [ - 32, - 32, - 3 - ], - "learning_rate": 0.1, - "nb_classes": 10 - } - }, - "scenario": { - "export_batches": false, - "kwargs": {}, - "module": "armory.scenarios.poisoning_sleeper_agent", - "name": "SleeperAgentScenario" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "set_pythonhashseed": true, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/mnist_baseline.json b/docs/scenario_configs/mnist_baseline.json deleted file mode 120000 index 890941cbc..000000000 --- a/docs/scenario_configs/mnist_baseline.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/mnist/mnist_baseline.json \ No newline at end of file diff --git a/docs/scenario_configs/no_docker/carla_short.json b/docs/scenario_configs/no_docker/carla_short.json deleted file mode 100644 index 5a269f788..000000000 --- a/docs/scenario_configs/no_docker/carla_short.json +++ /dev/null @@ -1,75 +0,0 @@ -{ - "_description": "CARLA single modality object detection, contributed by MITRE Corporation", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "learning_rate": 0.01, - "max_iter": 2, - "verbose": true - }, - "module": "armory.art_experimental.attacks.carla_obj_det_patch", - "name": "CARLADapricotPatch", - "use_label": false - }, - "dataset": { - "batch_size": 1, - "eval_split": "dev", - "framework": "numpy", - "index": "[:2]", - "modality": "rgb", - "module": "armory.data.adversarial_datasets", - "name": "carla_obj_det_dev" - }, - "defense": { - "kwargs": { - "apply_fit": false, - "apply_predict": true, - "clip_values": [ - 0.0, - 1.0 - ], - "quality": 50 - }, - "module": "art.defences.preprocessor", - "name": "JpegCompression", - "type": "Preprocessor" - }, - "metric": { - "means": true, - "perturbation": "l0", - "record_metric_per_sample": false, - "task": [ - "carla_od_AP_per_class", - "carla_od_disappearance_rate", - "carla_od_hallucinations_per_image", - "carla_od_misclassification_rate", - "carla_od_true_positive_rate" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": { - "num_classes": 4 - }, - "module": "armory.baseline_models.pytorch.carla_single_modality_object_detection_frcnn", - "name": "get_art_model", - "weights_file": "carla_rgb_weights.pt", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.carla_object_detection", - "name": "CarlaObjectDetectionTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": "colour-science/colour", - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/no_docker/cifar_short.json b/docs/scenario_configs/no_docker/cifar_short.json deleted file mode 100644 index 2788e40a1..000000000 --- a/docs/scenario_configs/no_docker/cifar_short.json +++ /dev/null @@ -1,60 +0,0 @@ -{ - "_description": "Baseline cifar10 image classification", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.031, - "eps_step": 0.007, - "max_iter": 2, - "num_random_init": 1, - "random_eps": false, - "targeted": false, - "verbose": false - }, - "module": "art.attacks.evasion", - "name": "ProjectedGradientDescent", - "use_label": true - }, - "dataset": { - "batch_size": 5, - "framework": "numpy", - "index": "[:10]", - "module": "armory.data.datasets", - "name": "cifar10" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 1 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.cifar", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/poisoning_cifar10_witches_brew.json b/docs/scenario_configs/poisoning_cifar10_witches_brew.json deleted file mode 120000 index 407aaca05..000000000 --- a/docs/scenario_configs/poisoning_cifar10_witches_brew.json +++ /dev/null @@ -1 +0,0 @@ -eval5/poisoning/cifar10_witches_brew.json \ No newline at end of file diff --git a/docs/scenario_configs/poisoning_gtsrb_dirty_label.json b/docs/scenario_configs/poisoning_gtsrb_dirty_label.json deleted file mode 120000 index 068b781e5..000000000 --- a/docs/scenario_configs/poisoning_gtsrb_dirty_label.json +++ /dev/null @@ -1 +0,0 @@ -eval5/poisoning/gtsrb_dlbd_baseline_pytorch.json \ No newline at end of file diff --git a/docs/scenario_configs/so2sat_eo_masked_pgd.json b/docs/scenario_configs/so2sat_eo_masked_pgd.json deleted file mode 120000 index 9ae3fcbc6..000000000 --- a/docs/scenario_configs/so2sat_eo_masked_pgd.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/so2sat/so2sat_eo_masked_pgd_undefended.json \ No newline at end of file diff --git a/docs/scenario_configs/speaker_id_librispeech.json b/docs/scenario_configs/speaker_id_librispeech.json deleted file mode 120000 index c9d0b713e..000000000 --- a/docs/scenario_configs/speaker_id_librispeech.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/speaker_id_librispeech/librispeech_baseline_sincnet_snr_pgd.json \ No newline at end of file diff --git a/docs/scenario_configs/tests/broken/invalid_dataset_framework.json b/docs/scenario_configs/tests/broken/invalid_dataset_framework.json deleted file mode 100644 index b2c958c42..000000000 --- a/docs/scenario_configs/tests/broken/invalid_dataset_framework.json +++ /dev/null @@ -1,56 +0,0 @@ -{ - "_description": "", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks", - "name": "FastGradientMethod" - }, - "dataset": { - "batch_size": 64, - "framework": "chainer", - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 3 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.mnist", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/tests/broken/invalid_module.json b/docs/scenario_configs/tests/broken/invalid_module.json deleted file mode 100644 index 72b42713b..000000000 --- a/docs/scenario_configs/tests/broken/invalid_module.json +++ /dev/null @@ -1,49 +0,0 @@ -{ - "_description": "Test schema with an invalid `attack.module`", - "adhoc": { - "batch_size": 64, - "epochs": 3 - }, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art::attacks", - "name": "FastGradientMethod" - }, - "dataset": { - "batch_size": 64, - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": null, - "model": { - "fit": true, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.keras_mnist", - "name": "get_art_model", - "weights_file": "", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "tests.evals.fgm_attack", - "name": "fgm_attack" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/tests/broken/missing_scenario.json b/docs/scenario_configs/tests/broken/missing_scenario.json deleted file mode 100644 index c3432ffdf..000000000 --- a/docs/scenario_configs/tests/broken/missing_scenario.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "_description": "", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks", - "name": "FastGradientMethod" - }, - "dataset": { - "batch_size": 64, - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 3 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.keras.mnist", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/tests/pytorch/image_classification.json b/docs/scenario_configs/tests/pytorch/image_classification.json deleted file mode 100644 index 0aad097a3..000000000 --- a/docs/scenario_configs/tests/pytorch/image_classification.json +++ /dev/null @@ -1,56 +0,0 @@ -{ - "_description": "", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": true, - "fit_kwargs": { - "nb_epochs": 3 - }, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.mnist", - "name": "get_art_model", - "weights_file": null, - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/tests/pytorch/image_classification_pretrained.json b/docs/scenario_configs/tests/pytorch/image_classification_pretrained.json deleted file mode 100644 index 015f04cc3..000000000 --- a/docs/scenario_configs/tests/pytorch/image_classification_pretrained.json +++ /dev/null @@ -1,54 +0,0 @@ -{ - "_description": "", - "adhoc": null, - "attack": { - "knowledge": "white", - "kwargs": { - "batch_size": 1, - "eps": 0.2, - "eps_step": 0.1, - "minimal": false, - "num_random_init": 0, - "targeted": false - }, - "module": "art.attacks.evasion", - "name": "FastGradientMethod" - }, - "dataset": { - "batch_size": 64, - "framework": "numpy", - "module": "armory.data.datasets", - "name": "mnist" - }, - "defense": null, - "metric": { - "means": true, - "perturbation": "linf", - "record_metric_per_sample": false, - "task": [ - "categorical_accuracy" - ] - }, - "model": { - "fit": false, - "fit_kwargs": {}, - "model_kwargs": {}, - "module": "armory.baseline_models.pytorch.mnist", - "name": "get_art_model", - "weights_file": "undefended_mnist_5epochs.pth", - "wrapper_kwargs": {} - }, - "scenario": { - "kwargs": {}, - "module": "armory.scenarios.image_classification", - "name": "ImageClassificationTask" - }, - "sysconfig": { - "docker_image": "twosixarmory/armory", - "external_github_repo": null, - "gpus": "all", - "output_dir": null, - "output_filename": null, - "use_gpu": false - } -} diff --git a/docs/scenario_configs/ucf101_masked_pgd.json b/docs/scenario_configs/ucf101_masked_pgd.json deleted file mode 120000 index 4df092b77..000000000 --- a/docs/scenario_configs/ucf101_masked_pgd.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/ucf101/ucf101_pretrained_masked_pgd_undefended.json \ No newline at end of file diff --git a/docs/scenario_configs/xview_robust_dpatch.json b/docs/scenario_configs/xview_robust_dpatch.json deleted file mode 120000 index 4289adfb4..000000000 --- a/docs/scenario_configs/xview_robust_dpatch.json +++ /dev/null @@ -1 +0,0 @@ -eval1-4/xview/xview_frcnn_robust_dpatch_undefended.json \ No newline at end of file diff --git a/examples/notebooks/api-walkthrough.ipynb b/examples/notebooks/api-walkthrough.ipynb deleted file mode 100644 index fbea4fefd..000000000 --- a/examples/notebooks/api-walkthrough.ipynb +++ /dev/null @@ -1,421 +0,0 @@ -{ - "cells": [ - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "# Armory Evaluation Declarations, Composition, and Modification\n", - "\n", - "There are data declarations in charmory.blocks that recapitulate standard evaluations\n", - "from the armory package. " - ] - }, - { - "cell_type": "code", - "execution_count": 1, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "2023-07-26 16:26:20 3s \u001b[33m\u001b[1mWARNING \u001b[0m \u001b[36mlogging\u001b[0m:\u001b[36mcallHandlers\u001b[0m:\u001b[36m1706\u001b[0m `tfds.core.add_checksums_dir` is deprecated. Refactor dataset in self-contained folders (`my_dataset/` folder containing my_dataset.py, my_dataset_test.py, dummy_data/, checksums.tsv). The checksum file will be automatically detected. More info at: https://www.tensorflow.org/datasets/add_dataset\n" - ] - } - ], - "source": [ - "import charmory.blocks.cifar10\n", - "\n", - "baseline = charmory.blocks.cifar10.baseline" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "The `baseline` evaluation is a composite dataclass with some metadata fields\n", - "describing the evaluation:" - ] - }, - { - "cell_type": "code", - "execution_count": 2, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "\"type(baseline)=\"\n", - "(\"baseline.name='cifar_baseline'\\n\"\n", - " \"baseline.description='Baseline cifar10 image classification'\\n\"\n", - " \"baseline.author='msw@example.com'\")\n" - ] - } - ], - "source": [ - "from pprint import pprint\n", - "pprint(f\"{type(baseline)=}\")\n", - "pprint(f\"{baseline.name=}\\n{baseline.description=}\\n{baseline.author=}\")" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "The charmory `Evaluation` class was called \"Experiment\" in prior versions of the\n", - "JATIC Armory library, but was renamed to avoid confusion with the MLflow conception\n", - "of Experiment, which is a collection of runs.\n", - "\n", - "Along with the metadata, an `Evaluation` contains some required components. The\n", - "`dataset` is a `Dataset` object, which specifies an Armory dataset and a pair\n", - "of necessary parameters:" - ] - }, - { - "cell_type": "code", - "execution_count": 3, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "(\"baseline.dataset=Dataset(name='CIFAR10', \"\n", - " 'test_dataset=, train_dataset=)')\n" - ] - } - ], - "source": [ - "pprint(f\"{baseline.dataset=}\")" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - " \n", - "the `function` parameter is shown first while details come afterwards; this allows quick\n", - "visibility of \"this is a cifar10 dataset\" from the `__str__` representation of the\n", - "object. An `Evaluation` also requires a `Model` and `Scenario`" - ] - }, - { - "cell_type": "code", - "execution_count": 4, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "(\"baseline.model=Model(name='pytorch cifar', \"\n", - " 'model=art.estimators.classification.pytorch.PyTorchClassifier(model=ModelWrapper(\\n'\n", - " ' (_model): Net(\\n'\n", - " ' (conv1): Conv2d(3, 4, kernel_size=(5, 5), stride=(1, 1))\\n'\n", - " ' (conv2): Conv2d(4, 10, kernel_size=(5, 5), stride=(1, 1))\\n'\n", - " ' (fc1): Linear(in_features=250, out_features=100, bias=True)\\n'\n", - " ' (fc2): Linear(in_features=100, out_features=10, bias=True)\\n'\n", - " ' )\\n'\n", - " '), loss=CrossEntropyLoss(), optimizer=Adam (\\n'\n", - " 'Parameter Group 0\\n'\n", - " ' amsgrad: False\\n'\n", - " ' betas: (0.9, 0.999)\\n'\n", - " ' capturable: False\\n'\n", - " ' differentiable: False\\n'\n", - " ' eps: 1e-08\\n'\n", - " ' foreach: None\\n'\n", - " ' fused: None\\n'\n", - " ' lr: 0.003\\n'\n", - " ' maximize: False\\n'\n", - " ' weight_decay: 0\\n'\n", - " '), input_shape=(32, 32, 3), nb_classes=10, channels_first=False, '\n", - " 'clip_values=array([0., 1.], dtype=float32), preprocessing_defences=None, '\n", - " 'postprocessing_defences=None, '\n", - " 'preprocessing=StandardisationMeanStdPyTorch(mean=0.0, std=1.0, '\n", - " 'apply_fit=True, apply_predict=True, device=cuda:0)), predict_kwargs={})')\n", - "('baseline.scenario=Scenario(function=, \"\n", - " 'kwargs={}, export_batches=True)')\n" - ] - } - ], - "source": [ - "pprint(f\"{baseline.model=}\")\n", - "pprint(f\"{baseline.scenario=}\")" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "Here we are using a prefab ART model and the standard Armory Image Classification Task\n", - "scenario.\n", - "\n", - "Because this is a \"baseline\" evaluation, it includes no defense, but does use a PGD\n", - "attack to calculate adversarial results.\n", - "\n", - "The optional `Metric` field tells Armory that we want to record additional metrics for\n", - "this evaluation. In this case, we are interested in the accuracy of the model on\n", - "adversarial examples." - ] - }, - { - "cell_type": "code", - "execution_count": 5, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "('baseline.attack=Attack(function=, \"\n", - " \"kwargs={'batch_size': 1, 'eps': 0.031, 'eps_step': 0.007, 'max_iter': 20, \"\n", - " \"'num_random_init': 1, 'random_eps': False, 'targeted': False, 'verbose': \"\n", - " \"False}, knowledge='white', use_label=True, type=None, generate_kwargs={}, \"\n", - " 'sweep_params={}, targeted=False, targeted_labels={})')\n", - "(\"baseline.metric=Metric(profiler_type='basic', \"\n", - " \"supported_metrics=['accuracy'], perturbation=['linf'], \"\n", - " \"task=['categorical_accuracy'], means=True, record_metric_per_sample=False)\")\n" - ] - } - ], - "source": [ - "pprint(f\"{baseline.attack=}\")\n", - "pprint(f\"{baseline.metric=}\")" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "The `charmory.blocks` module is intended as a convenient parts cabinet that allows\n", - "users to quickly assemble evaluations using standard components. They behave as standard\n", - "Python objects, so you can alter the canned definitions:" - ] - }, - { - "cell_type": "code", - "execution_count": 6, - "metadata": {}, - "outputs": [], - "source": [ - "baseline.metric = None" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "If you'd prefer to not have additional tracking. Also, the sub-components of an evaluation\n", - "are themselves objects, to be composed at user discretion:" - ] - }, - { - "cell_type": "code", - "execution_count": 7, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "charmory.blocks.cifar10.metric=Metric(profiler_type='basic', supported_metrics=['accuracy'], perturbation=['linf'], task=['categorical_accuracy'], means=True, record_metric_per_sample=False)\n" - ] - } - ], - "source": [ - "print(f\"{charmory.blocks.cifar10.metric=}\")\n", - "\n", - "# let's put the metric back into baseline\n", - "baseline.metric = charmory.blocks.cifar10.metric" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "Instantiation of the `Engine` class using the `Evaluation` object in `baseline` is\n", - "straightforward:" - ] - }, - { - "cell_type": "code", - "execution_count": 8, - "metadata": {}, - "outputs": [], - "source": [ - "import charmory.engine\n", - "engine = charmory.engine.EvaluationEngine(baseline)" - ] - }, - { - "cell_type": "code", - "execution_count": 9, - "metadata": {}, - "outputs": [ - { - "name": "stderr", - "output_type": "stream", - "text": [ - "Evaluation: 100%|██████████| 157/157 [09:53<00:00, 3.78s/it]" - ] - }, - { - "name": "stdout", - "output_type": "stream", - "text": [ - "2023-07-26 16:36:16 10m \u001b[34mMETRIC \u001b[0m \u001b[36marmory.instrument.instrument\u001b[0m:\u001b[36m_write\u001b[0m:\u001b[36m743\u001b[0m benign_mean_categorical_accuracy on benign examples w.r.t. ground truth labels: 0.0999\n", - "2023-07-26 16:36:16 10m \u001b[34mMETRIC \u001b[0m \u001b[36marmory.instrument.instrument\u001b[0m:\u001b[36m_write\u001b[0m:\u001b[36m743\u001b[0m adversarial_mean_categorical_accuracy on adversarial examples w.r.t. ground truth labels: 0.0773\n" - ] - }, - { - "name": "stderr", - "output_type": "stream", - "text": [ - "\n" - ] - } - ], - "source": [ - "result = engine.run()" - ] - }, - { - "cell_type": "code", - "execution_count": 10, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "{'armory_version': '23.4.0.post113+g0e7be67a.d20230713',\n", - " 'evaluation': Evaluation(name='cifar_baseline',\n", - " description='Baseline cifar10 image classification',\n", - " model=Model(name='pytorch cifar',\n", - " model=art.estimators.classification.pytorch.PyTorchClassifier(model=ModelWrapper(\n", - " (_model): Net(\n", - " (conv1): Conv2d(3, 4, kernel_size=(5, 5), stride=(1, 1))\n", - " (conv2): Conv2d(4, 10, kernel_size=(5, 5), stride=(1, 1))\n", - " (fc1): Linear(in_features=250, out_features=100, bias=True)\n", - " (fc2): Linear(in_features=100, out_features=10, bias=True)\n", - " )\n", - "), loss=CrossEntropyLoss(), optimizer=Adam (\n", - "Parameter Group 0\n", - " amsgrad: False\n", - " betas: (0.9, 0.999)\n", - " capturable: False\n", - " differentiable: False\n", - " eps: 1e-08\n", - " foreach: None\n", - " fused: None\n", - " lr: 0.003\n", - " maximize: False\n", - " weight_decay: 0\n", - "), input_shape=(32, 32, 3), nb_classes=10, channels_first=False, clip_values=array([0., 1.], dtype=float32), preprocessing_defences=None, postprocessing_defences=None, preprocessing=StandardisationMeanStdPyTorch(mean=0.0, std=1.0, apply_fit=True, apply_predict=True, device=cuda:0)),\n", - " predict_kwargs={}),\n", - " scenario=Scenario(function=,\n", - " kwargs={},\n", - " export_batches=True),\n", - " dataset=Dataset(name='CIFAR10',\n", - " test_dataset=,\n", - " train_dataset=),\n", - " author='msw@example.com',\n", - " attack=Attack(function=,\n", - " kwargs={'batch_size': 1,\n", - " 'eps': 0.031,\n", - " 'eps_step': 0.007,\n", - " 'max_iter': 20,\n", - " 'num_random_init': 1,\n", - " 'random_eps': False,\n", - " 'targeted': False,\n", - " 'verbose': False},\n", - " knowledge='white',\n", - " use_label=True,\n", - " type=None,\n", - " generate_kwargs={},\n", - " sweep_params={},\n", - " targeted=False,\n", - " targeted_labels={}),\n", - " metric=Metric(profiler_type='basic',\n", - " supported_metrics=['accuracy'],\n", - " perturbation=['linf'],\n", - " task=['categorical_accuracy'],\n", - " means=True,\n", - " record_metric_per_sample=False),\n", - " sysconfig=SysConfig(gpus=['all'], use_gpu=True)),\n", - " 'results': {'adversarial_mean_categorical_accuracy': [0.0773],\n", - " 'benign_mean_categorical_accuracy': [0.0999],\n", - " 'compute': {'Avg. CPU time (s) for 157 executions of Attack': 3.6688439361337464,\n", - " 'Avg. CPU time (s) for 157 executions of Inference': 0.013240570993672287},\n", - " 'perturbation_mean_linf': [0.03100001811236143]},\n", - " 'timestamp': 1690403183}\n" - ] - } - ], - "source": [ - "from pprint import pprint\n", - "pprint(result)" - ] - }, - { - "attachments": {}, - "cell_type": "markdown", - "metadata": {}, - "source": [ - "# Recap\n", - "\n", - "There is a bunch of explanation and debug prints in this notebook, but the\n", - "working code used is quite short:" - ] - }, - { - "cell_type": "code", - "execution_count": null, - "metadata": {}, - "outputs": [], - "source": [ - "import charmory.blocks.cifar10\n", - "import charmory.engine\n", - "\n", - "baseline = charmory.blocks.cifar10.baseline\n", - "engine = charmory.engine.EvaluationEngine(baseline)\n", - "result = engine.run()" - ] - } - ], - "metadata": { - "kernelspec": { - "display_name": ".venv", - "language": "python", - "name": "python3" - }, - "language_info": { - "codemirror_mode": { - "name": "ipython", - "version": 3 - }, - "file_extension": ".py", - "mimetype": "text/x-python", - "name": "python", - "nbconvert_exporter": "python", - "pygments_lexer": "ipython3", - "version": "3.11.4" - }, - "orig_nbformat": 4 - }, - "nbformat": 4, - "nbformat_minor": 2 -} diff --git a/examples/notebooks/import_experimental.ipynb b/examples/notebooks/import_experimental.ipynb deleted file mode 100644 index afbb81640..000000000 --- a/examples/notebooks/import_experimental.ipynb +++ /dev/null @@ -1,115 +0,0 @@ -{ - "cells": [ - { - "cell_type": "markdown", - "metadata": {}, - "source": [ - "The charmory and armory-examples packages have been installed with\n", - "\n", - " pip install -e .[all]\n", - " pip install -e examples[all]\n", - "\n", - "where the `all` is important. We confirm their installation with:" - ] - }, - { - "cell_type": "code", - "execution_count": 5, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "\u001b[01;31m\u001b[Karm\u001b[m\u001b[Kory-examples 23.8.post0+gb5668ede.d20230828 /home/msw/ch\u001b[01;31m\u001b[Karm\u001b[m\u001b[Kory/examples\n", - "ch\u001b[01;31m\u001b[Karm\u001b[m\u001b[Kory 23.8.post0+gb5668ede.d20230828 /home/msw/ch\u001b[01;31m\u001b[Karm\u001b[m\u001b[Kory\n" - ] - } - ], - "source": [ - "! python -m pip list | grep arm" - ] - }, - { - "cell_type": "markdown", - "metadata": {}, - "source": [ - "Import using package name. That is, we load the feature *module* and then \n", - "call a method from that module" - ] - }, - { - "cell_type": "code", - "execution_count": 6, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "short and stout\n" - ] - } - ], - "source": [ - "import charmory.experimental.feature as feature\n", - "print(feature.a_little_teapot(n=1))" - ] - }, - { - "cell_type": "markdown", - "metadata": {}, - "source": [ - "Now import a single method from the module" - ] - }, - { - "cell_type": "code", - "execution_count": 7, - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "kookaburra sits in the old gum tree\n" - ] - } - ], - "source": [ - "from charmory.experimental.feature import kookaburra\n", - "print(feature.kookaburra())\n" - ] - }, - { - "cell_type": "markdown", - "metadata": {}, - "source": [ - "Remember: if you are working on a notebook and add a new method to feature.py,\n", - "you must restart the Ipython kernel in order that it can see the new code." - ] - } - ], - "metadata": { - "kernelspec": { - "display_name": "cdao", - "language": "python", - "name": "python3" - }, - "language_info": { - "codemirror_mode": { - "name": "ipython", - "version": 3 - }, - "file_extension": ".py", - "mimetype": "text/x-python", - "name": "python", - "nbconvert_exporter": "python", - "pygments_lexer": "ipython3", - "version": "3.10.12" - }, - "orig_nbformat": 4 - }, - "nbformat": 4, - "nbformat_minor": 2 -} diff --git a/examples/notebooks/incr2honaker.ipynb b/examples/notebooks/incr2honaker.ipynb deleted file mode 100644 index c790e37e1..000000000 --- a/examples/notebooks/incr2honaker.ipynb +++ /dev/null @@ -1,640 +0,0 @@ -{ - "cells": [ - { - "cell_type": "markdown", - "id": "f204ae97", - "metadata": {}, - "source": [ - "## Step1: Basic Data Analysis, Data wrangling and Setup for PCA & Visualizations. " - ] - }, - { - "cell_type": "code", - "execution_count": 1, - "id": "4b853a97", - "metadata": { - "scrolled": true - }, - "outputs": [ - { - "data": { - "text/html": [ - "
\n", - "\n", - "\n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - "
Start TimeDurationRun IDNameSource TypeSource NameUserStatusJaticVisionDatasetGenerator._funcJaticVisionDatasetGenerator.batch_size...load_dataset.providerload_dataset.splitload_dataset.taskload_model._funcload_model.model_nameload_model.providerload_model.taskadversarial_mean_categorical_accuracybenign_mean_categorical_accuracyperturbation_mean_linf
02023-09-07 17:52:509.7min8e67d421ee3a46de947652d213227e7fgrandiose-lynx-117LOCALmodel_and_parameter_evaluation/mrm8488--convne...ubuntuFINISHEDcharmory.data.JaticVisionDatasetGenerator.__in...128...huggingfacevalidationimage-classificationjatic_toolbox._internals.interop.api.load_modelmrm8488/convnext-tiny-finetuned-eurosathuggingfaceimage-classification0.9451850.9851850.020000
12023-09-07 17:46:056.8mindb92fb7fb8d441cbb604f51c7fd7d624big-skink-852LOCALmodel_and_parameter_evaluation/mrm8488--convne...ubuntuFINISHEDcharmory.data.JaticVisionDatasetGenerator.__in...128...huggingfacevalidationimage-classificationjatic_toolbox._internals.interop.api.load_modelmrm8488/convnext-tiny-finetuned-eurosathuggingfaceimage-classification0.9737040.9851850.020000
22023-09-07 17:37:5623.7min995a5112f1d7455da35a9929bbcd62b9adorable-cow-816LOCALmodel_and_parameter_evaluation/nielsr--swin-ti...ubuntuFINISHEDcharmory.data.JaticVisionDatasetGenerator.__in...128...huggingfacevalidationimage-classificationjatic_toolbox._internals.interop.api.load_modelnielsr/swin-tiny-patch4-window7-224-finetuned-...huggingfaceimage-classification0.8055560.9781480.012000
32023-09-07 17:28:2417.7minedb723a7442940fb833ce809f13e9b64hilarious-yak-384LOCALmodel_and_parameter_evaluation/mrm8488--convne...ubuntuFINISHEDcharmory.data.JaticVisionDatasetGenerator.__in...128...huggingfacevalidationimage-classificationjatic_toolbox._internals.interop.api.load_modelmrm8488/convnext-tiny-finetuned-eurosathuggingfaceimage-classification0.8355560.9851850.018000
42023-09-07 17:26:4121.6minff28d01c25e144ecb2f682a6280f055cthundering-robin-603LOCALmodel_and_parameter_evaluation/nielsr--vit-fin...ubuntuFINISHEDcharmory.data.JaticVisionDatasetGenerator.__in...128...huggingfacevalidationimage-classificationjatic_toolbox._internals.interop.api.load_modelnielsr/vit-finetuned-eurosat-korniahuggingfaceimage-classification0.9214810.9666670.011997
\n", - "

5 rows × 40 columns

\n", - "
" - ], - "text/plain": [ - " Start Time Duration Run ID \\\n", - "0 2023-09-07 17:52:50 9.7min 8e67d421ee3a46de947652d213227e7f \n", - "1 2023-09-07 17:46:05 6.8min db92fb7fb8d441cbb604f51c7fd7d624 \n", - "2 2023-09-07 17:37:56 23.7min 995a5112f1d7455da35a9929bbcd62b9 \n", - "3 2023-09-07 17:28:24 17.7min edb723a7442940fb833ce809f13e9b64 \n", - "4 2023-09-07 17:26:41 21.6min ff28d01c25e144ecb2f682a6280f055c \n", - "\n", - " Name Source Type \\\n", - "0 grandiose-lynx-117 LOCAL \n", - "1 big-skink-852 LOCAL \n", - "2 adorable-cow-816 LOCAL \n", - "3 hilarious-yak-384 LOCAL \n", - "4 thundering-robin-603 LOCAL \n", - "\n", - " Source Name User Status \\\n", - "0 model_and_parameter_evaluation/mrm8488--convne... ubuntu FINISHED \n", - "1 model_and_parameter_evaluation/mrm8488--convne... ubuntu FINISHED \n", - "2 model_and_parameter_evaluation/nielsr--swin-ti... ubuntu FINISHED \n", - "3 model_and_parameter_evaluation/mrm8488--convne... ubuntu FINISHED \n", - "4 model_and_parameter_evaluation/nielsr--vit-fin... ubuntu FINISHED \n", - "\n", - " JaticVisionDatasetGenerator._func \\\n", - "0 charmory.data.JaticVisionDatasetGenerator.__in... \n", - "1 charmory.data.JaticVisionDatasetGenerator.__in... \n", - "2 charmory.data.JaticVisionDatasetGenerator.__in... \n", - "3 charmory.data.JaticVisionDatasetGenerator.__in... \n", - "4 charmory.data.JaticVisionDatasetGenerator.__in... \n", - "\n", - " JaticVisionDatasetGenerator.batch_size ... load_dataset.provider \\\n", - "0 128 ... huggingface \n", - "1 128 ... huggingface \n", - "2 128 ... huggingface \n", - "3 128 ... huggingface \n", - "4 128 ... huggingface \n", - "\n", - " load_dataset.split load_dataset.task \\\n", - "0 validation image-classification \n", - "1 validation image-classification \n", - "2 validation image-classification \n", - "3 validation image-classification \n", - "4 validation image-classification \n", - "\n", - " load_model._func \\\n", - "0 jatic_toolbox._internals.interop.api.load_model \n", - "1 jatic_toolbox._internals.interop.api.load_model \n", - "2 jatic_toolbox._internals.interop.api.load_model \n", - "3 jatic_toolbox._internals.interop.api.load_model \n", - "4 jatic_toolbox._internals.interop.api.load_model \n", - "\n", - " load_model.model_name load_model.provider \\\n", - "0 mrm8488/convnext-tiny-finetuned-eurosat huggingface \n", - "1 mrm8488/convnext-tiny-finetuned-eurosat huggingface \n", - "2 nielsr/swin-tiny-patch4-window7-224-finetuned-... huggingface \n", - "3 mrm8488/convnext-tiny-finetuned-eurosat huggingface \n", - "4 nielsr/vit-finetuned-eurosat-kornia huggingface \n", - "\n", - " load_model.task adversarial_mean_categorical_accuracy \\\n", - "0 image-classification 0.945185 \n", - "1 image-classification 0.973704 \n", - "2 image-classification 0.805556 \n", - "3 image-classification 0.835556 \n", - "4 image-classification 0.921481 \n", - "\n", - " benign_mean_categorical_accuracy perturbation_mean_linf \n", - "0 0.985185 0.020000 \n", - "1 0.985185 0.020000 \n", - "2 0.978148 0.012000 \n", - "3 0.985185 0.018000 \n", - "4 0.966667 0.011997 \n", - "\n", - "[5 rows x 40 columns]" - ] - }, - "execution_count": 1, - "metadata": {}, - "output_type": "execute_result" - } - ], - "source": [ - "import pandas as pd\n", - "from sklearn.preprocessing import StandardScaler\n", - "import plotly.graph_objects as go \n", - "import numpy as np\n", - "import seaborn as sns\n", - "import matplotlib.pyplot as plt\n", - "from sklearn.decomposition import PCA\n", - "df = pd.read_csv(\"eurosat_model_eval_09102023.csv\")\n", - "df.head()" - ] - }, - { - "cell_type": "code", - "execution_count": 2, - "id": "f68e39b6", - "metadata": {}, - "outputs": [], - "source": [ - "# PCA \n", - "features = ['ProjectedGradientDescent.eps', 'ProjectedGradientDescent.eps_step','ProjectedGradientDescent.max_iter']" - ] - }, - { - "cell_type": "code", - "execution_count": 3, - "id": "7e3a2333", - "metadata": {}, - "outputs": [], - "source": [ - "x = df.loc[:, features].values" - ] - }, - { - "cell_type": "code", - "execution_count": 4, - "id": "ad9d0c07", - "metadata": {}, - "outputs": [], - "source": [ - "y = df.loc[:,['adversarial_mean_categorical_accuracy']].values" - ] - }, - { - "cell_type": "code", - "execution_count": 5, - "id": "b52b3973", - "metadata": {}, - "outputs": [], - "source": [ - "x = StandardScaler().fit_transform(x)" - ] - }, - { - "cell_type": "code", - "execution_count": 6, - "id": "d80c1614", - "metadata": {}, - "outputs": [], - "source": [ - "pca = PCA(n_components=3)\n", - "\n", - "principalComponents = pca.fit_transform(x)\n", - "\n", - "principalDf = pd.DataFrame(data = principalComponents\n", - " , columns = ['principal component 1', 'principal component 2', 'principal component 3'])" - ] - }, - { - "cell_type": "code", - "execution_count": 7, - "id": "a19d65da", - "metadata": { - "scrolled": true - }, - "outputs": [ - { - "data": { - "text/html": [ - "
\n", - "\n", - "\n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - " \n", - "
principal component 1principal component 2principal component 3adversarial_mean_categorical_accuracy
01.277573-0.223385-0.00.945185
11.813629-0.7594410.00.973704
2-0.0363361.6790440.00.805556
3-0.2570311.4583490.00.835556
40.4997211.1429880.00.921481
...............
95-0.5301910.1130770.00.912963
96-0.714104-0.0708360.00.868148
97-0.5301910.1130770.00.839259
98-0.178047-0.606892-0.00.911481
990.005865-0.422980-0.00.930000
\n", - "

100 rows × 4 columns

\n", - "
" - ], - "text/plain": [ - " principal component 1 principal component 2 principal component 3 \\\n", - "0 1.277573 -0.223385 -0.0 \n", - "1 1.813629 -0.759441 0.0 \n", - "2 -0.036336 1.679044 0.0 \n", - "3 -0.257031 1.458349 0.0 \n", - "4 0.499721 1.142988 0.0 \n", - ".. ... ... ... \n", - "95 -0.530191 0.113077 0.0 \n", - "96 -0.714104 -0.070836 0.0 \n", - "97 -0.530191 0.113077 0.0 \n", - "98 -0.178047 -0.606892 -0.0 \n", - "99 0.005865 -0.422980 -0.0 \n", - "\n", - " adversarial_mean_categorical_accuracy \n", - "0 0.945185 \n", - "1 0.973704 \n", - "2 0.805556 \n", - "3 0.835556 \n", - "4 0.921481 \n", - ".. ... \n", - "95 0.912963 \n", - "96 0.868148 \n", - "97 0.839259 \n", - "98 0.911481 \n", - "99 0.930000 \n", - "\n", - "[100 rows x 4 columns]" - ] - }, - "execution_count": 7, - "metadata": {}, - "output_type": "execute_result" - } - ], - "source": [ - "finalDf = pd.concat([principalDf, df[['adversarial_mean_categorical_accuracy']]], axis = 1)\n", - "finalDf" - ] - }, - { - "cell_type": "code", - "execution_count": 8, - "id": "176a9389", - "metadata": {}, - "outputs": [], - "source": [ - "finalDf['model_name'] = df['load_model.model_name']" - ] - }, - { - "cell_type": "code", - "execution_count": 9, - "id": "cc6e92aa", - "metadata": {}, - "outputs": [ - { - "data": { - "image/png": "", - "text/plain": [ - "
" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "sns.set_style(\"white\")\n", - "\n", - "ax = sns.kdeplot(x=finalDf['principal component 1'], y=finalDf['principal component 2'],hue=finalDf['model_name'])\n", - "sns.move_legend(ax, \"lower center\", bbox_to_anchor=(.5, 1), ncol=3, title=None, frameon=False)\n", - "plt.show()" - ] - }, - { - "cell_type": "code", - "execution_count": 10, - "id": "d3083108", - "metadata": {}, - "outputs": [], - "source": [ - "finalDf_convnext = finalDf[finalDf.model_name == 'mrm8488/convnext-tiny-finetuned-eurosat']\n", - "finalDf_swin = finalDf[finalDf.model_name == 'nielsr/swin-tiny-patch4-window7-224-finetuned-eurosat']\n", - "finalDf_vit = finalDf[finalDf.model_name == 'nielsr/vit-finetuned-eurosat-kornia']" - ] - }, - { - "cell_type": "code", - "execution_count": 11, - "id": "f9e0653d", - "metadata": {}, - "outputs": [ - { - "data": { - "image/png": "", - "text/plain": [ - "
" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "sns.kdeplot(x=finalDf_convnext['principal component 1'], y=finalDf_convnext['principal component 2'])\n", - "plt.title('mrm8488/convnext-tiny-finetuned-eurosat')\n", - "plt.show()" - ] - }, - { - "cell_type": "code", - "execution_count": 12, - "id": "316c00fa", - "metadata": {}, - "outputs": [ - { - "data": { - "image/png": "", - "text/plain": [ - "
" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "sns.kdeplot(x=finalDf_swin['principal component 1'], y=finalDf_swin['principal component 2'])\n", - "plt.title('nielsr/swin-tiny-patch4-window7-224-finetuned-eurosat')\n", - "plt.show()" - ] - }, - { - "cell_type": "code", - "execution_count": 13, - "id": "991fde8e", - "metadata": {}, - "outputs": [ - { - "data": { - "image/png": "", - "text/plain": [ - "
" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "sns.kdeplot(x=finalDf_vit['principal component 1'], y=finalDf_vit['principal component 2'])\n", - "plt.title('nielsr/vit-finetuned-eurosat-kornia')\n", - "plt.show()" - ] - }, - { - "cell_type": "code", - "execution_count": null, - "id": "d20da7d5", - "metadata": {}, - "outputs": [], - "source": [] - } - ], - "metadata": { - "kernelspec": { - "display_name": "Python 3 (ipykernel)", - "language": "python", - "name": "python3" - }, - "language_info": { - "codemirror_mode": { - "name": "ipython", - "version": 3 - }, - "file_extension": ".py", - "mimetype": "text/x-python", - "name": "python", - "nbconvert_exporter": "python", - "pygments_lexer": "ipython3", - "version": "3.10.12" - } - }, - "nbformat": 4, - "nbformat_minor": 5 -} diff --git a/library/src/charmory/experimental/example_results.py b/library/src/charmory/experimental/example_results.py deleted file mode 100644 index 8f07a2834..000000000 --- a/library/src/charmory/experimental/example_results.py +++ /dev/null @@ -1,11 +0,0 @@ -from pprint import pprint - - -def print_outputs(dataset, model, results): - print("=" * 64) - pprint(dataset.train_dataloader) - pprint(dataset.test_dataloader) - print("-" * 64) - pprint(model) - print("=" * 64) - pprint(results) diff --git a/library/src/charmory/experimental/examples.py b/library/src/charmory/experimental/examples.py deleted file mode 100644 index 8171123d2..000000000 --- a/library/src/charmory/experimental/examples.py +++ /dev/null @@ -1,24 +0,0 @@ -import math -import random - -from matplotlib import pyplot as plt - - -def show_samples(dataset, samples=3, n_col=3): - """shows random selections from dataset with `samples` distinct labels""" - - chosen_labels = set() - chosen = [] - while len(chosen) < samples: - choice = random.choice(dataset) - label = choice["label"] - if label not in chosen_labels: - chosen.append(choice) - chosen_labels.add(label) - - n_row = math.ceil(samples / n_col) - _, axs = plt.subplots(n_row, n_col) - axs = axs.flatten() - for sample, ax in zip(chosen, axs): - ax.imshow(sample["image"]) - plt.show() diff --git a/library/src/charmory/experimental/feature.py b/library/src/charmory/experimental/feature.py deleted file mode 100644 index dfbc534d3..000000000 --- a/library/src/charmory/experimental/feature.py +++ /dev/null @@ -1,13 +0,0 @@ -"""boilerplate experimental charmory feature for demo purposes""" - - -def a_little_teapot(n: int) -> str: - return "short and stou" + ("t" * n) - - -def kookaburra() -> str: - import inspect - - frame = inspect.currentframe() - function_name = frame.f_code.co_name if frame is not None else "" - return f"{function_name} sits in the old gum tree" diff --git a/library/src/charmory/experimental/food_track.py b/library/src/charmory/experimental/food_track.py deleted file mode 100644 index 860f59fdb..000000000 --- a/library/src/charmory/experimental/food_track.py +++ /dev/null @@ -1,124 +0,0 @@ -"""An mlflow experiment with varying parameters""" - -from pprint import pprint - -import art.attacks.evasion -from art.estimators.classification import PyTorchClassifier -import numpy as np -import torch -from transformers.image_utils import infer_channel_dimension_format - -from armory.metrics.compute import BasicProfiler -from charmory.data import ArmoryDataLoader -from charmory.engine import EvaluationEngine -from charmory.evaluation import Attack, Dataset, Evaluation, Metric, Model -from charmory.model.image_classification import JaticImageClassificationModel -from charmory.tasks.image_classification import ImageClassificationTask -from charmory.track import track_evaluation, track_init_params, track_params -from charmory.utils import create_jatic_dataset_transform - -NAME = "jatic-food-category-classification" -DESCRIPTION = "Food category classification from HuggingFace via JATIC-toolbox" - - -def make_evaluation_from_scratch(epsilon: float) -> Evaluation: - """construct an evaluation with a variable epsilon.""" - - import jatic_toolbox - - model = track_params(jatic_toolbox.load_model)( - provider="huggingface", - model_name="Kaludi/food-category-classification-v2.0", - task="image-classification", - ) - - classifier = track_init_params(PyTorchClassifier)( - JaticImageClassificationModel(model), - loss=torch.nn.CrossEntropyLoss(), - optimizer=torch.optim.Adam(model.parameters(), lr=0.003), - input_shape=(224, 224, 3), - channels_first=False, - nb_classes=12, - clip_values=(0.0, 1.0), - ) - - dataset = track_params(jatic_toolbox.load_dataset)( - provider="huggingface", - dataset_name="Kaludi/food-category-classification-v2.0", - task="image-classification", - split="validation", - ) - - def filter(sample): - try: - infer_channel_dimension_format(np.asarray(sample["image"])) - return True - except Exception as err: - print(err) - return False - - print(f"Dataset length prior to filtering: {len(dataset)}") - dataset._dataset = dataset._dataset.filter(filter) - print(f"Dataset length after filtering: {len(dataset)}") - - transform = create_jatic_dataset_transform(model.preprocessor) - dataset.set_transform(transform) - - generator = ArmoryDataLoader( - dataset=dataset, - batch_size=16, - ) - - eval_dataset = Dataset( - name="food-category-classification", - x_key="image", - y_key="label", - test_dataloader=generator, - ) - - eval_model = Model( - name="food-category-classification", - model=classifier, - ) - - eval_attack = Attack( - name="PGD", - attack=track_init_params(art.attacks.evasion.ProjectedGradientDescent)( - classifier, - batch_size=1, - eps=epsilon, - eps_step=0.007, - max_iter=20, - num_random_init=1, - random_eps=False, - targeted=False, - verbose=False, - ), - use_label_for_untargeted=True, - ) - - eval_metric = Metric( - profiler=BasicProfiler(), - ) - - evaluation = Evaluation( - name=NAME, - description=DESCRIPTION, - author="Kaludi", - dataset=eval_dataset, - model=eval_model, - attack=eval_attack, - metric=eval_metric, - ) - - return evaluation - - -for epsilon in [x / 1000.0 for x in range(10, 40, 5)]: - with track_evaluation("msw-food-3", "epsilon 0.010 to 0.040"): - evaluation = make_evaluation_from_scratch(epsilon=epsilon) - task = ImageClassificationTask(evaluation, num_classes=12) - engine = EvaluationEngine(task) - results = engine.run() - print(f"Completed evaluation run with {epsilon=}") - pprint(results) diff --git a/library/src/charmory/msw-foods.py b/library/src/charmory/msw-foods.py deleted file mode 100644 index 3440f599b..000000000 --- a/library/src/charmory/msw-foods.py +++ /dev/null @@ -1,123 +0,0 @@ -"""An mlflow experiment with varying parameters""" - -from pprint import pprint - -import art.attacks.evasion -from art.estimators.classification import PyTorchClassifier -import jatic_toolbox -import numpy as np -import torch -from transformers.image_utils import infer_channel_dimension_format - -from armory.metrics.compute import BasicProfiler -from charmory.data import ArmoryDataLoader -from charmory.engine import EvaluationEngine -from charmory.evaluation import Attack, Dataset, Evaluation, Metric, Model -from charmory.model.image_classification import JaticImageClassificationModel -from charmory.tasks.image_classification import ImageClassificationTask -from charmory.track import track_evaluation, track_init_params, track_params -from charmory.utils import create_jatic_dataset_transform - -NAME = "jatic-food-category-classification" -DESCRIPTION = "Food category classification from HuggingFace via JATIC-toolbox" - - -def make_evaluation_from_scratch(epsilon: float) -> Evaluation: - """construct an evaluation with a variable epsilon.""" - - model = track_params(jatic_toolbox.load_model)( - provider="huggingface", - model_name="Kaludi/food-category-classification-v2.0", - task="image-classification", - ) - - classifier = track_init_params(PyTorchClassifier)( - JaticImageClassificationModel(model), - loss=torch.nn.CrossEntropyLoss(), - optimizer=torch.optim.Adam(model.parameters(), lr=0.003), - input_shape=(224, 224, 3), - channels_first=False, - nb_classes=12, - clip_values=(0.0, 1.0), - ) - - dataset = track_params(jatic_toolbox.load_dataset)( - provider="huggingface", - dataset_name="Kaludi/food-category-classification-v2.0", - task="image-classification", - split="validation", - ) - - def filter(sample): - try: - infer_channel_dimension_format(np.asarray(sample["image"])) - return True - except Exception as err: - print(err) - return False - - print(f"Dataset length prior to filtering: {len(dataset)}") - dataset._dataset = dataset._dataset.filter(filter) - print(f"Dataset length after filtering: {len(dataset)}") - - transform = create_jatic_dataset_transform(model.preprocessor) - dataset.set_transform(transform) - - generator = ArmoryDataLoader( - dataset=dataset, - batch_size=16, - ) - - eval_dataset = Dataset( - name="food-category-classification", - x_key="image", - y_key="label", - test_dataloader=generator, - ) - - eval_model = Model( - name="food-category-classification", - model=classifier, - ) - - eval_attack = Attack( - name="PGD", - attack=track_init_params(art.attacks.evasion.ProjectedGradientDescent)( - classifier, - batch_size=1, - eps=epsilon, - eps_step=0.007, - max_iter=20, - num_random_init=1, - random_eps=False, - targeted=False, - verbose=False, - ), - use_label_for_untargeted=True, - ) - - eval_metric = Metric( - profiler=BasicProfiler(), - ) - - evaluation = Evaluation( - name=NAME, - description=DESCRIPTION, - author="Kaludi", - dataset=eval_dataset, - model=eval_model, - attack=eval_attack, - metric=eval_metric, - ) - - return evaluation - - -for epsilon in [x / 1000.0 for x in range(10, 40, 5)]: - with track_evaluation("msw-food-3", "epsilon 0.010 to 0.040"): - evaluation = make_evaluation_from_scratch(epsilon=epsilon) - task = ImageClassificationTask(evaluation, num_classes=12) - engine = EvaluationEngine(task) - results = engine.run() - print(f"Completed evaluation run with {epsilon=}") - pprint(results)