File size: 11,214 Bytes
9d14f67 |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 |
Downloading https://www.cs.toronto.edu/~kriz/cifar-10-python.tar.gz to ../data/cifar-10-python.tar[85/5761] 100%|βββββββββββββββββββββββββββββββββββββββββββββββββββββ| 170498071/170498071 [00:01<00:00, 86462452.39it /s] Extracting ../data/cifar-10-python.tar.gz to ../data Files already downloaded and verified Files already downloaded and verified Clean accuracy: 93.27% setting parameters for standard version using standard version including apgd-ce, apgd-t, fab-t, square. initial accuracy: 93.27% apgd-ce - 1/37 - 53 out of 256 successfully perturbed apgd-ce - 2/37 - 53 out of 256 successfully perturbed apgd-ce - 3/37 - 55 out of 256 successfully perturbed apgd-ce - 4/37 - 58 out of 256 successfully perturbed apgd-ce - 5/37 - 45 out of 256 successfully perturbed apgd-ce - 6/37 - 55 out of 256 successfully perturbed apgd-ce - 7/37 - 45 out of 256 successfully perturbed apgd-ce - 8/37 - 56 out of 256 successfully perturbed apgd-ce - 9/37 - 49 out of 256 successfully perturbed apgd-ce - 10/37 - 54 out of 256 successfully perturbed apgd-ce - 11/37 - 42 out of 256 successfully perturbed apgd-ce - 12/37 - 47 out of 256 successfully perturbed apgd-ce - 13/37 - 57 out of 256 successfully perturbed apgd-ce - 14/37 - 53 out of 256 successfully perturbed apgd-ce - 15/37 - 60 out of 256 successfully perturbed apgd-ce - 16/37 - 41 out of 256 successfully perturbed apgd-ce - 17/37 - 60 out of 256 successfully perturbed apgd-ce - 18/37 - 57 out of 256 successfully perturbed apgd-ce - 19/37 - 64 out of 256 successfully perturbed apgd-ce - 20/37 - 48 out of 256 successfully perturbed apgd-ce - 21/37 - 43 out of 256 successfully perturbed apgd-ce - 22/37 - 69 out of 256 successfully perturbed apgd-ce - 23/37 - 53 out of 256 successfully perturbed apgd-ce - 24/37 - 44 out of 256 successfully perturbed apgd-ce - 25/37 - 58 out of 256 successfully perturbed apgd-ce - 26/37 - 62 out of 256 successfully perturbed apgd-ce - 27/37 - 57 out of 256 successfully perturbed apgd-ce - 28/37 - 60 out of 256 successfully perturbed apgd-ce - 29/37 - 50 out of 256 successfully perturbed apgd-ce - 30/37 - 53 out of 256 successfully perturbed apgd-ce - 31/37 - 57 out of 256 successfully perturbed apgd-ce - 32/37 - 56 out of 256 successfully perturbed apgd-ce - 33/37 - 48 out of 256 successfully perturbed apgd-ce - 34/37 - 48 out of 256 successfully perturbed apgd-ce - 35/37 - 54 out of 256 successfully perturbed apgd-ce - 36/37 - 54 out of 256 successfully perturbed apgd-ce - 37/37 - 19 out of 111 successfully perturbed robust accuracy after APGD-CE: 73.90% (total time 1815.9 s) apgd-t - 1/29 - 6 out of 256 successfully perturbed apgd-t - 2/29 - 11 out of 256 successfully perturbed apgd-t - 3/29 - 5 out of 256 successfully perturbed apgd-t - 4/29 - 6 out of 256 successfully perturbed apgd-t - 5/29 - 9 out of 256 successfully perturbed apgd-t - 6/29 - 10 out of 256 successfully perturbed apgd-t - 7/29 - 4 out of 256 successfully perturbed apgd-t - 8/29 - 16 out of 256 successfully perturbed apgd-t - 9/29 - 7 out of 256 successfully perturbed apgd-t - 10/29 - 11 out of 256 successfully perturbed apgd-t - 11/29 - 9 out of 256 successfully perturbed apgd-t - 12/29 - 7 out of 256 successfully perturbed apgd-t - 13/29 - 8 out of 256 successfully perturbed apgd-t - 14/29 - 10 out of 256 successfully perturbed apgd-t - 15/29 - 11 out of 256 successfully perturbed apgd-t - 16/29 - 13 out of 256 successfully perturbed apgd-t - 17/29 - 20 out of 256 successfully perturbed apgd-t - 18/29 - 12 out of 256 successfully perturbed apgd-t - 19/29 - 11 out of 256 successfully perturbed apgd-t - 20/29 - 14 out of 256 successfully perturbed apgd-t - 21/29 - 15 out of 256 successfully perturbed apgd-t - 22/29 - 5 out of 256 successfully perturbed apgd-t - 23/29 - 5 out of 256 successfully perturbed apgd-t - 24/29 - 8 out of 256 successfully perturbed apgd-t - 25/29 - 17 out of 256 successfully perturbed apgd-t - 26/29 - 12 out of 256 successfully perturbed apgd-t - 27/29 - 8 out of 256 successfully perturbed apgd-t - 28/29 - 6 out of 256 successfully perturbed apgd-t - 29/29 - 6 out of 222 successfully perturbed robust accuracy after APGD-T: 71.08% (total time 14360.6 s) fab-t - 1/28 - 0 out of 256 successfully perturbed fab-t - 2/28 - 0 out of 256 successfully perturbed fab-t - 3/28 - 0 out of 256 successfully perturbed fab-t - 4/28 - 0 out of 256 successfully perturbed fab-t - 5/28 - 0 out of 256 successfully perturbed fab-t - 6/28 - 0 out of 256 successfully perturbed fab-t - 7/28 - 0 out of 256 successfully perturbed fab-t - 8/28 - 0 out of 256 successfully perturbed fab-t - 9/28 - 0 out of 256 successfully perturbed fab-t - 10/28 - 0 out of 256 successfully perturbed fab-t - 11/28 - 1 out of 256 successfully perturbed fab-t - 12/28 - 0 out of 256 successfully perturbed fab-t - 13/28 - 0 out of 256 successfully perturbed fab-t - 14/28 - 0 out of 256 successfully perturbed fab-t - 15/28 - 0 out of 256 successfully perturbed fab-t - 16/28 - 0 out of 256 successfully perturbed fab-t - 17/28 - 0 out of 256 successfully perturbed fab-t - 18/28 - 0 out of 256 successfully perturbed fab-t - 19/28 - 0 out of 256 successfully perturbed fab-t - 20/28 - 0 out of 256 successfully perturbed fab-t - 21/28 - 0 out of 256 successfully perturbed fab-t - 22/28 - 0 out of 256 successfully perturbed fab-t - 23/28 - 0 out of 256 successfully perturbed fab-t - 24/28 - 0 out of 256 successfully perturbed fab-t - 25/28 - 0 out of 256 successfully perturbed fab-t - 26/28 - 0 out of 256 successfully perturbed fab-t - 27/28 - 0 out of 256 successfully perturbed fab-t - 28/28 - 0 out of 196 successfully perturbed robust accuracy after FAB-T: 71.07% (total time 37176.5 s) square - 1/28 - 0 out of 256 successfully perturbed square - 2/28 - 0 out of 256 successfully perturbed square - 3/28 - 0 out of 256 successfully perturbed square - 4/28 - 0 out of 256 successfully perturbed square - 5/28 - 0 out of 256 successfully perturbed square - 6/28 - 0 out of 256 successfully perturbed square - 7/28 - 0 out of 256 successfully perturbed square - 8/28 - 0 out of 256 successfully perturbed square - 9/28 - 0 out of 256 successfully perturbed square - 10/28 - 0 out of 256 successfully perturbed square - 11/28 - 0 out of 256 successfully perturbed square - 12/28 - 0 out of 256 successfully perturbed square - 13/28 - 0 out of 256 successfully perturbed square - 14/28 - 0 out of 256 successfully perturbed square - 15/28 - 0 out of 256 successfully perturbed square - 16/28 - 0 out of 256 successfully perturbed square - 17/28 - 0 out of 256 successfully perturbed square - 18/28 - 0 out of 256 successfully perturbed square - 19/28 - 0 out of 256 successfully perturbed square - 20/28 - 0 out of 256 successfully perturbed square - 21/28 - 0 out of 256 successfully perturbed square - 22/28 - 0 out of 256 successfully perturbed square - 23/28 - 0 out of 256 successfully perturbed square - 24/28 - 0 out of 256 successfully perturbed square - 25/28 - 0 out of 256 successfully perturbed square - 26/28 - 0 out of 256 successfully perturbed square - 27/28 - 0 out of 256 successfully perturbed square - 28/28 - 0 out of 195 successfully perturbed robust accuracy after SQUARE: 71.07% (total time 84616.4 s) max Linf perturbation: 0.03137, nan in tensor: 0, max: 1.00000, min: 0.00000 robust accuracy: 71.07% Adversarial accuracy: 71.07% |