You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The problem is that input_var has already been mapped to tanh-space, so it's in fact not the original input. However, the adversarial example input_adv is the one to be used. Therefore, without mapping input_var back to its original space, the dist calculated won't be the true L2 distance between the adversarial example and the original image. In Carlini's code he performed the exact operation. Thanks for checking!
The text was updated successfully, but these errors were encountered:
In
attacks.AttackCarliniWagnerL2._optimize
there's:The problem is that
input_var
has already been mapped to tanh-space, so it's in fact not the original input. However, the adversarial exampleinput_adv
is the one to be used. Therefore, without mappinginput_var
back to its original space, thedist
calculated won't be the true L2 distance between the adversarial example and the original image. In Carlini's code he performed the exact operation. Thanks for checking!The text was updated successfully, but these errors were encountered: