You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I notice you only use dist <= self.epsilon to indicate the success boolean. However, imaging a situation that the distance/distortion between self.x_final and original image is below predefined epsilon, but it is classified correctly by the classifier!
Are you sure this code can deal with this situation. https://github.com/uclaml/RayS/blob/master/RayS.py#L77
The text was updated successfully, but these errors were encountered:
machanic
changed the title
Does all found x_final is attacked successfully?
Does all found x_final with dist <= self.epsilon is attacked successfully?
Jan 9, 2021
Please note that self.x_final is initialized far away from the original (dist = infty) and is only been updated when a successful attack is founded. Therefore your imagined case never happens.
I notice you only use
dist <= self.epsilon
to indicate the success boolean. However, imaging a situation that the distance/distortion betweenself.x_final
and original image is below predefined epsilon, but it is classified correctly by the classifier!Are you sure this code can deal with this situation.
https://github.com/uclaml/RayS/blob/master/RayS.py#L77
The text was updated successfully, but these errors were encountered: