Training : Model was trained for both classes 4000 images and trained on 1000 images, Epochs = 5. The pipeline of the project involves augmenting the images to standard tensor size of (3,224,224), and for 5 epochs to train network independent of the oder of the images getting trained. Augmentation of image involves mirroring , shrinking , padding , rotating and padding to improve the robustness in training.

Network Model:

Layer (type:depth-idx) Output Shape Param #

ImageClassifier [1, 2]

├─Sequential: 1-1 [1, 64, 112, 112]

│ └─Conv2d: 2-1 [1, 64, 224, 224] 1,792 │ └─ReLU: 2-2 [1, 64, 224, 224]

│ └─BatchNorm2d: 2-3 [1, 64, 224, 224] 128 │ └─MaxPool2d: 2-4 [1, 64, 112, 112]

├─Sequential: 1-2 [1, 512, 56, 56]

│ └─Conv2d: 2-5 [1, 512, 112, 112] 295,424 │ └─ReLU: 2-6 [1, 512, 112, 112]

│ └─BatchNorm2d: 2-7 [1, 512, 112, 112] 1,024 │ └─MaxPool2d: 2-8 [1, 512, 56, 56]

├─Sequential: 1-3 [1, 512, 28, 28]

│ └─Conv2d: 2-9 [1, 512, 56, 56] 2,359,808 │ └─ReLU: 2-10 [1, 512, 56, 56]

│ └─BatchNorm2d: 2-11 [1, 512, 56, 56] 1,024 │ └─MaxPool2d: 2-12 [1, 512, 28, 28]

├─Sequential: 1-4 [1, 512, 14, 14] (recursive) │ └─Conv2d: 2-13 [1, 512, 28, 28] (recursive) │ └─ReLU: 2-14 [1, 512, 28, 28]

│ └─BatchNorm2d: 2-15 [1, 512, 28, 28] (recursive) │ └─MaxPool2d: 2-16 [1, 512, 14, 14] ├─Sequential: 1-5 [1, 512, 7, 7] (recursive) │ └─Conv2d: 2-17 [1, 512, 14, 14] (recursive) │ └─ReLU: 2-18 [1, 512, 14, 14]

│ └─BatchNorm2d: 2-19 [1, 512, 14, 14] (recursive) │ └─MaxPool2d: 2-20 [1, 512, 7, 7]

├─Sequential: 1-6 [1, 512, 3, 3] (recursive) │ └─Conv2d: 2-21 [1, 512, 7, 7] (recursive) │ └─ReLU: 2-22 [1, 512, 7, 7]

│ └─BatchNorm2d: 2-23 [1, 512, 7, 7] (recursive) │ └─MaxPool2d: 2-24 [1, 512, 3, 3]

├─Sequential: 1-7 [1, 2]

│ └─Flatten: 2-25 [1, 4608]

│ └─Linear: 2-26 [1, 2] 9,218

Total params: 2,668,418 Trainable params: 2,668,418

Attack: FGSM(Fast Gradient Sign Method ) Xadv = x - ϵ.sign(∇xJ(θ,x,ytarget)) x-Clean Input Image J-Lossfunction Ytarget - Target Label ϵ - Epsilon When ϵ=0 ,is image in which perturbation is not performed, whereas ϵ=1, Image is perturbed largely.

● Research Background: Fgsm attack attacks the gradient and perturbs the image ,Most of the defense techniques that deals with these attack are denoising, random padding and averaging.
● Theoretical Ananlysis: The attack is performed to check how robust is classifier , Even human can still distinguish the both class after perturbation ,but to train the model such robustness attackand defense techniques are performed. Defense mitigates by denoising the perturbations and makes feasible for classifier to distinguish.
● Implementation: Dataset I used was cat_vs_dog , network architecture is shown above. The model was trained for 4000 images and tested for 1000 images. Defense technique will be performed by augmenting the attacked image through various techniques such as random padding and denoising.
● Numerical Analysis: Attack is performed for different values of the epsilon(0 , 0.05, 0.1, 0.15, 0.2, 0.25, 0.3), and model is trained to classify the perturbed image and below is the image that model misclassifies the
● Suggested Improvements: To improve the classification, denising techniques which averages the neighbor pixels to remove noise and augment the image , and then fed back to network to improve accuracy.The model is attached to the following file as pth extension and collab notebook

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support