In [None]:
import os
os.chdir('/nfs/homedirs/ayle/guided-research/SNIP-it/')

In [None]:
import torch
from torchvision import datasets, transforms
import foolbox as fb
from experiments.main import load_checkpoint
from models import GeneralModel
from models.statistics.Metrics import Metrics
from utils.config_utils import *
from utils.model_utils import *
from utils.system_utils import *
from utils.attacks_utils import get_attack
from torch.utils.data.dataset import Dataset
from copy import deepcopy
from utils.metrics import calculate_aupr, calculate_auroc
from utils.attacks_utils import construct_adversarial_examples
import matplotlib.pyplot as plt
from tqdm import tqdm
import torch.nn.functional as F
from torch.distributions import Categorical

In [None]:
arguments = dict({
'eval_freq': 1000,  # evaluate every n batches
    'save_freq': 1e6,  # save model every n epochs, besides before and after training
    'batch_size': 512,  # size of batches, for Imagenette 128
    'seed': 1234,  # random seed
    'max_training_minutes': 6120 , # one hour and a 45 minutes max, process killed after n minutes (after finish of epoch)
    'plot_weights_freq': 50, # plot pictures to tensorboard every n epochs
    'prune_freq': 1, # if pruning during training: how long to wait before starting
    'prune_delay': 0, # "if pruning during training: 't' from algorithm box, interval between pruning events, default=0
    'prune_to': 0,
    'epochs': 0,
    'rewind_to': 0, # rewind to this epoch if rewinding is done
    'snip_steps': 5, # 's' in algorithm box, number of pruning steps for 'rule of thumb', TODO
    'snip_iter': 1000,
    'pruning_rate': 0.0, # pruning rate passed to criterion at pruning event. however, most override this
    'growing_rate': 0.0000 , # grow back so much every epoch (for future criterions)
    'pruning_limit': 0.0,  # Prune until here, if structured in nodes, if unstructured in weights. most criterions use this instead of the pruning_rate
    'local_pruning': 0,
    'learning_rate': 2e-3,
    'grad_clip': 10,
    'grad_noise': 0 , # added gaussian noise to gradients
    'l2_reg': 5e-5 , # weight decay
    'l1_reg': 0 , # l1-norm regularisation
    'lp_reg': 0 , # lp regularisation with p < 1
    'l0_reg': 1.0 , # l0 reg lambda hyperparam
    'hoyer_reg': 0.001 , # hoyer reg lambda hyperparam
    'beta_ema': 0.999 , # l0 reg beta ema hyperparam

    'loss': 'CrossEntropy',
    'optimizer': 'ADAM',
    'model': 'ResNet18',  # ResNet not supported with structured
    'data_set': 'CIFAR10',
    'ood_data_set': 'SVHN',
    'ood_data_set_prune': 'SVHN',
    'prune_criterion': 'WeightImportance',  # options: SNIP, SNIPit, SNIPitDuring, UnstructuredRandom, GRASP, HoyerSquare, IMP, // SNAPit, StructuredRandom, GateDecorators, EfficientConvNets, GroupHoyerSquare
    'train_scheme': 'DefaultTrainer' , # default: DefaultTrainer
    'attack': 'FGSM',
    'epsilon': 6,
    'eval_ood_data_sets': ['SVHN', 'CIFAR100'],
    'eval_attacks': ['FGSM'],
    'eval_epsilons': [8, 48],

    'device': 'cuda',
    'results_dir': "tmp",

    'checkpoint_name': None,
    'checkpoint_model': None,

    'disable_cuda_benchmark': 1 , # speedup (disable) vs reproducibility (leave it)
    'eval': 0,
    'disable_autoconfig': 0 , # for the brave
    'preload_all_data': 0 , # load all data into ram memory for speedups
    'tuning': 0 , # splits trainset into train and validationset, omits test set

    'get_hooks': 0,
    'track_weights': 0 , # "keep statistics on the weights through training
    'disable_masking': 1 , # disable the ability to prune unstructured
    'enable_rewinding': 0, # enable the ability to rewind to previous weights
    'outer_layer_pruning': 1, # allow to prune outer layers (unstructured) or not (structured)
    'first_layer_dense': 0,
    'random_shuffle_labels': 0  ,# run with random-label experiment from zhang et al
    'l0': 0,  # run with l0 criterion, might overwrite some other arguments
    'hoyer_square': 0, # "run in unstructured DeephoyerSquare criterion, might overwrite some other arguments
    'group_hoyer_square': 0 ,# run in unstructured Group-DeephoyerSquare criterion, might overwrite some other arguments

    'disable_histograms': 0,
    'disable_saliency': 0,
    'disable_confusion': 0,
    'disable_weightplot': 0,
    'disable_netplot': 0,
    'skip_first_plot': 0,
    'disable_activations': 0,
    
#     'input_dim': [1, 28, 28],
#       'output_dim': 10,
#       'hidden_dim': [512],
#       'N': 60000,
    
    'input_dim': [3, 32, 32],
    'output_dim': 10,
    'hidden_dim': [512],
    'N': 60000,
    'mean': (0.4914, 0.4822, 0.4465),
    'std': (0.2471, 0.2435, 0.2616)
})

In [None]:
DATASET_PATH = '/nfs/students/ayle/guided-research/gitignored/data'

In [None]:
metrics = Metrics()
out = metrics.log_line
metrics._batch_size = arguments['batch_size']
metrics._eval_freq = arguments['eval_freq']
set_results_dir(arguments["results_dir"])

In [None]:
model: GeneralModel = find_right_model(
        NETWORKS_DIR, arguments['model'],
        device=arguments['device'],
        hidden_dim=arguments['hidden_dim'],
        input_dim=arguments['input_dim'],
        output_dim=arguments['output_dim'],
        is_maskable=arguments['disable_masking'],
        is_tracking_weights=arguments['track_weights'],
        is_rewindable=arguments['enable_rewinding'],
        is_growable=arguments['growing_rate'] > 0,
        outer_layer_pruning=arguments['outer_layer_pruning'],
        maintain_outer_mask_anyway=(
                                       not arguments['outer_layer_pruning']) and (
                                           "Structured" in arguments['prune_criterion']),
        l0=arguments['l0'],
        l0_reg=arguments['l0_reg'],
        N=arguments['N'],
        beta_ema=arguments['beta_ema'],
        l2_reg=arguments['l2_reg']
).to(arguments['device'])

In [None]:
load_checkpoint(arguments, model, out)

In [None]:
def load_checkpoint(path, model, out):
    with open(path, 'rb') as f:
        state = pickle.load(f)
    try:
        model.load_state_dict(state)
    except KeyError as e:
        print(list(state.keys()))
        raise e
    out(f"Loaded checkpoint {path}")
    
# def load_checkpoint(path, model, out):
#     state_dict = torch.load(path)
#     new_state_dict = {}
#     for key, val in state_dict.items():
#         if key == 'aug.width': continue
        
#         new_key = '.'.join(['m'] + key.split('.')[1:])
#         new_state_dict[new_key] = val
#     model.load_state_dict(new_state_dict)
#     out(f"Loaded checkpoint {path}")

In [None]:
# path = '/nfs/students/ayle/guided-research/results/Conv6/2021-07-12_03.45.39_model=Conv6_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/Conv6_finished.pickle'
# path = '/nfs/students/ayle/guided-research/results/Conv6/2021-07-12_04.48.17_model=Conv6_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=2345/models/Conv6_finished.pickle'
# path = '/nfs/students/ayle/guided-research/results/Conv6/2021-07-15_19.21.19_model=Conv6_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=3456/models/Conv6_finished.pickle'
# path = '/nfs/students/ayle/guided-research/results/Conv6/2021-07-15_19.25.40_model=Conv6_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=4567/models/Conv6_finished.pickle'
# path = '/nfs/students/ayle/guided-research/results/Conv6/2021-07-15_19.25.40_model=Conv6_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=4567/models/Conv6_finished.pickle'

# path = '/nfs/students/ayle/guided-research/results/LeNet5/2021-07-11_03.10.29_model=LeNet5_dataset=FASHION_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/LeNet5_finished.pickle'

# path = '/nfs/students/ayle/guided-research/results/ResNet18/2021-07-13_11.03.15_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

path = '/nfs/students/ayle/guided-research/results/ResNet18/2021-07-26_22.46.19_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'
# path2 = '/nfs/students/ayle/guided-research/results/ResNet18/2021-07-26_23.33.17_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=2345/models/ResNet18_finished.pickle'
# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-07-26_23.35.18_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=3456/models/ResNet18_finished.pickle'
# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-07-26_23.35.46_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=4567/models/ResNet18_finished.pickle'
# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-07-26_23.36.23_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=5678/models/ResNet18_finished.pickle'

# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/VGG16/2021-08-22_11.02.10_model=VGG16_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/VGG16_finished.pickle'

# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-08-29_13.57.22_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-08-29_18.19.04_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

# path = '/nfs/homedirs/ayle/guided-research/SNIP-it/gitignored/results/ResNet18/2021-08-24_11.36.47_model=ResNet18_dataset=CIFAR10_prune-criterion=EarlyJohn_pruning-limit=0.94_prune-freq=1_prune-delay=0_outer-layer-pruning=1_prune-to=10_rewind-to=0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

# path = '/nfs/students/ayle/guided-research/gitignored/results/tests/2021-09-21_10.19.16_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

# model trained on augerino augmentations
# path = '/nfs/students/ayle/guided-research/gitignored/results/tests/2021-09-24_11.30.01_model=ResNet18_dataset=CIFAR10_prune-criterion=EmptyCrit_pruning-limit=0.0_train-scheme=DefaultTrainer_seed=1234/models/ResNet18_finished.pickle'

# augerino
# path = '/nfs/students/ayle/guided-research/gitignored/results/invariances/aug_no_trans_trained.pt'
# path = '/nfs/students/ayle/guided-research/gitignored/results/invariances/aug_fixed_trans_new_hyperparam_b512_trained.pt'

load_checkpoint(path, model, out)


In [None]:
device = arguments['device']

In [None]:
# augmentation stuff
# width = torch.load("/nfs/students/ayle/guided-research/gitignored/results/invariances/aug_fixed_trans_trained_width.pt")
width = torch.load("/nfs/students/ayle/guided-research/gitignored/results/invariances/aug_fixed_trans_new_hyperparam_b512_trained_width.pt")
# width = torch.load("/nfs/students/ayle/guided-research/gitignored/results/invariances/aug_no_trans_new_hyperparam_b512_trained_width.pt")

from augerino import models 
aug = models.UniformAug()
aug.set_width(width.data)

In [None]:
# load data
train_loader, test_loader = find_right_model(
    DATASETS, arguments['data_set'],
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

# load OOD data
_, ood_loader = find_right_model(
    DATASETS, arguments['ood_data_set'],
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

In [None]:
# load OOD data
ood_prune_loader, _ = find_right_model(
    DATASETS, arguments['ood_data_set_prune'],
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

# get loss function
loss = find_right_model(
    LOSS_DIR, arguments['loss'],
    device=device,
    l1_reg=arguments['l1_reg'],
    lp_reg=arguments['lp_reg'],
    l0_reg=arguments['l0_reg'],
    hoyer_reg=arguments['hoyer_reg']
)

# get optimizer
optimizer = find_right_model(
    OPTIMS, arguments['optimizer'],
    params=model.parameters(),
    lr=arguments['learning_rate'],
    weight_decay=arguments['l2_reg'] if not arguments['l0'] else 0
)

In [None]:
backup_model = deepcopy(model)

In [None]:
run_name = f'_model={arguments["model"]}_dataset={arguments["data_set"]}_ood-dataset={arguments["ood_data_set"]}' + \
           f'_attack={arguments["attack"]}_epsilon={arguments["epsilon"]}_prune-criterion={arguments["prune_criterion"]}' + \
           f'_pruning-limit={arguments["pruning_limit"]}_prune-freq={arguments["prune_freq"]}_prune-delay={arguments["prune_delay"]}' + \
           f'_rewind-to={arguments["rewind_to"]}_train-scheme={arguments["train_scheme"]}_seed={arguments["seed"]}'


criterion = find_right_model(
        CRITERION_DIR, arguments['prune_criterion'],
        model=model,
        limit=arguments['pruning_limit'],
        start=0.5,
        orig_scores=True,
        steps=arguments['snip_steps'],
        device=arguments['device'],
        arguments=arguments
    )

# build trainer
trainer = find_right_model(
    TRAINERS_DIR, arguments['train_scheme'],
    model=model,
    loss=loss,
    optimizer=optimizer,
    device=device,
    arguments=arguments,
    train_loader=train_loader,
    test_loader=test_loader,
    ood_loader=ood_loader,
    ood_prune_loader=ood_prune_loader,
    metrics=metrics,
    criterion=criterion,
    run_name=run_name
)

trainer.train()

In [None]:
orig_grads = criterion.grads_abs

In [None]:
orig_mean = criterion.scores_mean
orig_std = criterion.scores_std
layer_names = list(orig_grads.keys())

In [None]:
# for name, val in orig_grads.items():
#     orig_grads[name] = (val.cpu() - orig_mean[name]) / (1e-8 + orig_std[name])

In [None]:
# backup_model = deepcopy(model)

In [None]:
arguments['batch_size'] = 2

# load data
train_loader, test_loader = find_right_model(
    DATASETS, arguments['data_set'],
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

# load OOD data
_, ood_loader = find_right_model(
    DATASETS, arguments['ood_data_set'],
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

In [None]:
norms = []
per_layer_norms = []
for i, (x, y) in enumerate(tqdm(test_loader)):
    if i == int(len(test_loader)*0.1): break
    
    model = deepcopy(backup_model)
    model.eval()

    x = x.cuda()

    new_x = [x]
    for im in x:
        for _ in range(5):
            image = aug(im.unsqueeze(0))
            new_x.append(image)
    x = torch.cat(new_x)

    out = model(x)
    preds = out.argmax(dim=-1, keepdim=True).flatten()

    train_loader = [(x, preds)]

#     train_loader = []
#     for im in x:
#         batch = []
        
#         batch.append(im.unsqueeze(0))
#         for _ in range(50):
#             new_x = aug(deepcopy(im.unsqueeze(0)))
#             batch.append(new_x)
#         batch = torch.cat(batch)
#         out = model(batch)
#         pred = out.argmax(dim=-1, keepdim=True).flatten()
        
#         train_loader.append((batch, pred))
        
    # get criterion
    criterion = find_right_model(
        CRITERION_DIR, arguments['prune_criterion'],
        model=model,
        limit=arguments['pruning_limit'],
        start=0.5,
        steps=arguments['snip_steps'],
        device=arguments['device'],
        arguments=arguments
    )
    
    criterion.prune(arguments['pruning_limit'],
                        train_loader=train_loader,
                      ood_loader=None,
                      local=arguments['local_pruning'],
                      manager=None)
    
    layer_norms = []
    for j, (grad1, grad2) in enumerate(zip(orig_grads.values(), criterion.grads_abs.values())):
        grad3 = (grad2.cpu() - orig_mean[layer_names[j]]) /  (1e-8 + orig_std[layer_names[j]])
#         grad3 = grad2
        layer_norms.append(torch.norm(grad1.cpu() - grad3, p=5).cpu().detach().numpy())
    per_layer_norms.append(layer_norms)
    norms.append(np.mean(layer_norms))

In [None]:
np.mean(norms)

In [None]:
# Load CIFAR100 OOD data
_, ood_loader = find_right_model(
    DATASETS, "SVHN",
    arguments=arguments,
    mean=arguments['mean'],
    std=arguments['std']
)

In [None]:
# OOD data

ood_norms = []
ood_per_layer_norms = []

for i, (x, y) in enumerate(tqdm(ood_loader)):
    if i == int(len(test_loader)*0.1): break
    
    model = deepcopy(backup_model)
    model.eval()

    x = x.cuda()

    new_x = [x]
    for im in x:
        for _ in range(20):
            image = aug(im.unsqueeze(0))
            new_x.append(image)
    x = torch.cat(new_x)

    out = model(x)
    preds = out.argmax(dim=-1, keepdim=True).flatten()

    train_loader = [(x, preds)]

#     train_loader = []
#     for im in x:
#         batch = []
        
#         batch.append(im.unsqueeze(0))
#         for _ in range(50):
#             new_x = aug(deepcopy(im.unsqueeze(0)))
#             batch.append(new_x)
#         batch = torch.cat(batch)
#         out = model(batch)
#         pred = out.argmax(dim=-1, keepdim=True).flatten()
        
#         train_loader.append((batch, pred))
    
    # get criterion
    criterion = find_right_model(
        CRITERION_DIR, arguments['prune_criterion'],
        model=model,
        limit=arguments['pruning_limit'],
        start=0.5,
        steps=arguments['snip_steps'],
        device=arguments['device'],
        arguments=arguments
    )
    
    criterion.prune(arguments['pruning_limit'],
                        train_loader=train_loader,
                      ood_loader=None,
                      local=arguments['local_pruning'],
                      manager=None)
    
    layer_norms = []
    for j, (grad1, grad2) in enumerate(zip(orig_grads.values(), criterion.grads_abs.values())):
        grad3 = (grad2.cpu() - orig_mean[layer_names[j]]) /  (1e-8 + orig_std[layer_names[j]])
#         grad3 = grad2
        layer_norms.append(torch.norm(grad1.cpu() - grad3, p=5).cpu().detach().numpy())
    per_layer_norms.append(layer_norms)
    ood_norms.append(np.mean(layer_norms))

In [None]:
# Attacks
from torchvision import datasets
from utils.constants import DATASET_PATH
mean=arguments['mean']
std=arguments['std']
test_set = datasets.CIFAR10(root=DATASET_PATH, train=False, transform=transforms.ToTensor())
test_loader = torch.utils.data.DataLoader(
        test_set,
        batch_size=arguments['batch_size'],
        shuffle=False,
        pin_memory=True,
        num_workers=4
    )

trans = transforms.Normalize(mean, std)

# Attacks
ood_norms = []
attack_per_layer_norms = []

for i, (x, y) in enumerate(tqdm(test_loader)):
    if i == int(len(test_loader)*0.1): break
    
    model = deepcopy(backup_model)
    model.eval()
        
    adv_results, predictions = construct_adversarial_examples(x, y, 'FGSM', model, model.device, 8, False, False)
    _, advs, success = adv_results
    x = advs.cpu()
        
    new_x = []
    for image in x:
        image = trans(image.squeeze()).unsqueeze(0)
        new_x.append(image)
    x = torch.cat(new_x)
    
    x = x.cuda()
    
#     new_x = [x]
#     for im in x:
#         for _ in range(5):
#             image = aug(im.unsqueeze(0))
#             new_x.append(image)
#     x = torch.cat(new_x)

#     out = model(x)
#     preds = out.argmax(dim=-1, keepdim=True).flatten()

#     train_loader = [(x, preds)]

    train_loader = []
    for im in x:
        batch = []
        
        batch.append(im.unsqueeze(0))
        for _ in range(5):
            new_x = aug(deepcopy(im.unsqueeze(0)))
            batch.append(new_x)
        batch = torch.cat(batch)
        out = model(batch)
        pred = out.argmax(dim=-1, keepdim=True).flatten()
        
        train_loader.append((batch, pred))
    
    # get criterion
    criterion = find_right_model(
        CRITERION_DIR, arguments['prune_criterion'],
        model=model,
        limit=arguments['pruning_limit'],
        start=0.5,
        steps=arguments['snip_steps'],
        device=arguments['device'],
        arguments=arguments
    )
    
    criterion.prune(arguments['pruning_limit'],
                    train_loader=train_loader,
                      ood_loader=None,
                      local=arguments['local_pruning'],
                      manager=None)
    
    layer_norms = []
    for j, (grad1, grad2) in enumerate(zip(orig_grads.values(), criterion.grads_abs.values())):
        grad3 = (grad2.cpu() - orig_mean[layer_names[j]]) /  (1e-8 + orig_std[layer_names[j]])
#         grad3 = grad2
        layer_norms.append(torch.norm(grad1.cpu() - grad3, p=5).cpu().detach().numpy())
    attack_per_layer_norms.append(layer_norms)
    ood_norms.append(np.mean(layer_norms))

In [None]:
# DS

ds_path = os.path.join(DATASET_PATH, "cifar10_corrupted")
aurocs = []
ds_per_layer_norms = []
        
for ds_dataset_name in os.listdir(ds_path):
    if ds_dataset_name.endswith('5.npz'):
        npz_dataset = np.load(os.path.join(ds_path, ds_dataset_name))

        ds_dataset = CIFAR10C(npz_dataset["images"], npz_dataset["labels"], arguments["mean"], arguments["std"])
        ds_loader = torch.utils.data.DataLoader(
            ds_dataset,
            batch_size=arguments['batch_size'],
            shuffle=False,
            pin_memory=True,
            num_workers=4
        )

        ood_norms = []
        for i, (x, y) in enumerate(tqdm(ds_loader)):
            if i == int(len(test_loader)*0.1): break
            
            model = deepcopy(backup_model)
            model.eval()
            
            x = x.cuda()
            
            new_x = [x]
            for im in x:
                for _ in range(5):
                    image = aug(im.unsqueeze(0))
                    new_x.append(image)
            x = torch.cat(new_x)
            
            out = model(x)
            preds = out.argmax(dim=-1, keepdim=True).flatten()

            train_loader = [(x, preds)]

            # get criterion
            criterion = find_right_model(
                CRITERION_DIR, arguments['prune_criterion'],
                model=model,
                limit=arguments['pruning_limit'],
                start=0.5,
                steps=arguments['snip_steps'],
                device=arguments['device'],
                arguments=arguments
            )

            criterion.prune(arguments['pruning_limit'],
                              train_loader=train_loader,
                              ood_loader=None,
                              local=arguments['local_pruning'],
                              manager=None)

            layer_norms = []
            for j, (grad1, grad2) in enumerate(zip(orig_grads.values(), criterion.grads_abs.values())):
                grad3 = (grad2.cpu() - orig_mean[layer_names[j]]) /  (1e-8 + orig_std[layer_names[j]])
    #                 grad3 = grad2
                layer_norms.append(torch.norm(grad1 - grad3, p=5).cpu().detach().numpy())
            ds_per_layer_norms.append(layer_norms)
            ood_norms.append(np.mean(layer_norms))

        auroc = calculate_auroc(np.concatenate((np.zeros_like(norms), np.ones_like(ood_norms))), np.concatenate((norms, ood_norms)))
        print('AUROC', auroc)
        aurocs.append(auroc)
        
print('Mean AUROC', np.mean(aurocs))

In [None]:
np.mean(ood_norms)

In [None]:
norms = np.array(norms)
ood_norms = np.array(ood_norms)

In [None]:
calculate_auroc(np.concatenate((np.zeros_like(norms), np.ones_like(ood_norms))), np.concatenate((norms, ood_norms)))

In [None]:
0.932336

In [None]:
# 0.9999251152073733 batch size 10 dropout eval model train, not layers 0 3 7
# 0.9999873271889401 batch size 10 model train, not layers 0 3 7
# 0.9999592933947773 batch size 10 model train, all layers

In [None]:
plt.plot(np.array(per_layer_norms).mean(0), label='In-distribution')
plt.plot(np.array(ood_per_layer_norms).mean(0), label='Out-Of-Distribution')
# plt.plot(np.array(attack_per_layer_norms).mean(0), label='Attack (FGSM \u03B5 = 8)')
# plt.plot(np.array(ds_per_layer_norms).mean(0), label='Distribution Shifts')
plt.legend()
plt.xlabel('ResNet18 layers')
plt.ylabel('L2 distance to original scores')

In [None]:
# np.array(ood_per_layer_norms).mean(0)

In [None]:
thresholds, _ = torch.topk(torch.tensor(norms), int(len(norms)*0.05), sorted=True)

In [None]:
threshold = thresholds[-1]

In [None]:
num_detected = 0
for ood_norm in ood_norms:
    if ood_norm >= threshold:
        num_detected += 1

In [None]:
num_detected / len(ood_norms)