-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
weird FGSM accuracy on MNIST clean data #111
Comments
Hi @chhyun ,I am facing the same problem as you. I got too low accuracy in my case for FGSM (epsilon=0.1, 0.3):
My guess here is how the epsilon is calculated. Should we normalized epsilon as |
Hi @ZhangYuef. I used 0.3 as epsilon to FGSM attack my natural trained MNIST model and got 49% adversarial accuracy. |
Please dump full hyper parameters. The variance between your result and the expected is far beyond the margin of error. |
I tried FGSM attack on MNIST clean dataset, and I got 49% accuracy,
which is too large compared to 6.4% [Madry, https://arxiv.org/pdf/1706.06083.pdf]
Am i missing something?
I'd like to ask if anyone else has done a FGSM attack against mnist, what performance you got?.
The text was updated successfully, but these errors were encountered: