# Tensorflow Fruits360-VGG16 Patch Demo

>⚠️ **Warning:** This demo assumes that you have access to an on-prem deployment of Dioptra that provides a copy of the Fruits360 dataset and a CUDA-compatible GPU.
> This demo cannot be run on a typical personal computer.

This notebook demonstrates the adversarial patch attack applied on the VGG16 model, as well as adversarial training defenses.

The following two sections cover experiment setup and is similar across all demos.

## Setup: Experiment Name and Fruits360 Dataset

Here we will import the necessary Python modules and ensure the proper environment variables are set so that all the code blocks will work as expected.

**Important: Users will need to verify or update the following parameters:**

- Ensure that the `USERNAME` parameter is set to your own name.
- Ensure that the `DATASET_DIR` parameter is set to the location of the Fruits360 dataset directory. Currently set to `/nfs/data/Fruits360-Kaggle-2019/fruits-360` as the default location.
- (Optional) Set the `EXPERIMENT_NAME` parameter to your own preferred experiment name.

Other parameters can be modified to alter the RESTful API and MLFlow tracking addresses. 

In [1]:
# Import packages from the Python standard library
import os
import pprint
import time
import warnings
from pathlib import Path
from typing import Tuple

# Filter out warning messages
warnings.filterwarnings("ignore")

# Please enter custom username here.
USERNAME = "howard"

# Ensure that the dataset location is properly set here.
DATASET_DIR = "/nfs/data/Fruits360-Kaggle-2019/fruits-360"

# Experiment name (note the username_ prefix convention)
EXPERIMENT_NAME = f"{USERNAME}_fruits360_adversarial_patches"

# Address for connecting the docker container to exposed ports on the host device
HOST_DOCKER_INTERNAL = "host.docker.internal"
# HOST_DOCKER_INTERNAL = "172.17.0.1"

# Testbed API ports
RESTAPI_PORT = "30080"
MLFLOW_TRACKING_PORT = "35000"

# Default address for accessing the RESTful API service
RESTAPI_ADDRESS = (
    f"http://{HOST_DOCKER_INTERNAL}:{RESTAPI_PORT}"
    if os.getenv("IS_JUPYTER_SERVICE")
    else f"http://localhost:{RESTAPI_PORT}"
)

# Override the AI_RESTAPI_URI variable, used to connect to RESTful API service
os.environ["AI_RESTAPI_URI"] = RESTAPI_ADDRESS

# Default address for accessing the MLFlow Tracking server
MLFLOW_TRACKING_URI = (
    f"http://{HOST_DOCKER_INTERNAL}:{MLFLOW_TRACKING_PORT}"
    if os.getenv("IS_JUPYTER_SERVICE")
    else f"http://localhost:{MLFLOW_TRACKING_PORT}"
)

# Path to custom task plugins archives
CUSTOM_PLUGINS_EVALUATION_TAR_GZ = Path("custom-plugins-evaluation.tar.gz")

# Override the MLFLOW_TRACKING_URI variable, used to connect to MLFlow Tracking service
os.environ["MLFLOW_TRACKING_URI"] = MLFLOW_TRACKING_URI

# Base API address
RESTAPI_API_BASE = f"{RESTAPI_ADDRESS}/api"

# Path to workflows archive
WORKFLOWS_TAR_GZ = Path("workflows.tar.gz")

# Import third-party Python packages
import numpy as np
import requests
from mlflow.tracking import MlflowClient

# Import utils.py file
import utils

# Create random number generator
rng = np.random.default_rng(54399264723942495723666216079516778448)

## Dataset

The training and testing images in this directory are saved as JPEG files and are organized into the following folder structure:

    fruits360
    ├── Test
    │   ├── Apple Braeburn
    │   ├── Apple Crimson Snow
    │   ├── Apple Golden 1
    │   ├── Apple Golden 2
    │   ├── Apple Golden 3
    │   ├── ...
    │   └── Walnut
    ├── Training
    │   ├── Apple Braeburn
    │   ├── Apple Crimson Snow
    │   ├── Apple Golden 1
    │   ├── Apple Golden 2
    │   ├── Apple Golden 3
    │   ├── ...
    │   └── Walnut

The subfolders under `fruits360/Training/` and `fruits360/Test` are the classification labels for the images in the dataset.
There are 120 labels or subfolders for the training and test sets.
This folder structure is a standardized way to encode the label information and many libraries can make use of it, including the Tensorflow library that we are using for this particular demo.

## Submit and run jobs

The entrypoints that we will be running in this example are implemented in the Python source files under `src/` and the `MLproject` file.
To run these entrypoints within the testbed architecture, we need to package those files up into an archive and submit it to the Testbed RESTful API to create a new job.
For convenience, the `Makefile` provides a rule for creating the archive file for this example, just run `make workflows`,

In [2]:
%%bash

# Create the workflows.tar.gz file
make workflows

make: Nothing to be done for 'workflows'.


  and should_run_async(code)


To connect with the endpoint, we will use a client class defined in the `utils.py` file that is able to connect with the Testbed RESTful API using the HTTP protocol.
We connect using the client below, which uses the environment variable `AI_RESTAPI_URI` to figure out how to connect to the Testbed RESTful API,

In [3]:
restapi_client = utils.SecuringAIClient()

  and should_run_async(code)


We need to register an experiment under which to collect our job runs.
The code below checks if the relevant experiment exists.
If it does, then it just returns info about the experiment, if it doesn't, it then registers the new experiment.

In [4]:
response_experiment = restapi_client.get_experiment_by_name(name=EXPERIMENT_NAME)

if response_experiment is None or "Not Found" in response_experiment.get("message", []):
    response_experiment = restapi_client.register_experiment(name=EXPERIMENT_NAME)

response_experiment

{'experimentId': 11,
 'createdOn': '2020-11-05T09:37:19.652250',
 'lastModified': '2020-11-05T09:37:19.652250',
 'name': 'howard_fruits360_adversarial_patches'}

We should also check which queues are available for running our jobs to make sure that the resources that we need are available.
The code below queries the Testbed API and returns a list of active queues.

In [5]:
restapi_client.list_queues()

[{'name': 'tensorflow_cpu',
  'createdOn': '2020-11-20T17:46:06.756687',
  'lastModified': '2020-11-20T17:46:06.756687',
  'queueId': 1},
 {'name': 'tensorflow_gpu',
  'createdOn': '2020-11-20T18:00:40.876888',
  'lastModified': '2020-11-20T18:00:40.876888',
  'queueId': 2},
 {'name': 'pytorch_cpu',
  'createdOn': '2020-11-20T19:52:36.079781',
  'lastModified': '2020-11-20T19:52:36.079781',
  'queueId': 5},
 {'name': 'pytorch_gpu',
  'createdOn': '2020-11-20T19:52:43.348460',
  'lastModified': '2020-11-20T19:52:43.348460',
  'queueId': 7}]

This example also makes use of the `custom_fgm_patch_poisoning_plugins` custom task plugin package stored locally under the `task-plugins/securingai_custom/custom_fgm_patch_poisoning_plugins` directory.
To register these custom task plugins, we first need to package them up into an archive.
For convenience, the `Makefile` provides a rule for creating the custom task plugins archive file, just run `make custom-plugins`,

In [6]:
%%bash

# Create the workflows.tar.gz file
make custom-plugins

make: Nothing to be done for 'custom-plugins'.


Now that the custom task plugin package is packaged into an archive file, next we register it by uploading the file to the REST API.
Note that we need to provide the name to use for custom task plugin package, this name must be unique under the custom task plugins namespace.
For a full list of the custom task plugins, use `restapi_client.restapi_client.list_custom_task_plugins()`.

In [7]:
restapi_client.delete_custom_task_plugin(name="custom_fgm_patch_poisoning_plugins")
response_custom_plugins = restapi_client.get_custom_task_plugin(name="custom_fgm_patch_poisoning_plugins")

if response_custom_plugins is None or "Not Found" in response_custom_plugins.get("message", []):
    response_custom_plugins = restapi_client.upload_custom_plugin_package(
        custom_plugin_name="custom_fgm_patch_poisoning_plugins",
        custom_plugin_file=CUSTOM_PLUGINS_EVALUATION_TAR_GZ,
    )

response_custom_plugins

  and should_run_async(code)


{'modules': ['data_tensorflow.py',
  'tensorflow.py',
  'attacks_patch.py',
  'registry_art.py',
  '__init__.py',
  'estimators_keras_classifiers.py',
  'import_keras.py',
  'defenses_image_preprocessing.py'],
 'taskPluginName': 'custom_fgm_patch_poisoning_plugins',
 'collection': 'securingai_custom'}

If at any point you need to update one or more files within the `evaluation` plugin package, you will need to unregister/delete the custom task plugin first using the REST API.
This can be done as follows,

```python
# Delete the 'evaluation' custom task plugin package
restapi_client.delete_custom_task_plugin(name="custom_fgm_patch_poisoning_plugins")
```

## Adversarial Patches: Baseline Training

Now, we will train our baseline VGG16 model on the Fruits360 dataset. 
We will be submitting our jobs to the `"tensorflow_gpu"` queue.
Once the experiment is finished, we will examine the accuracy results of our model.

In [8]:
response_vgg16_train = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="train",
    entry_point_kwargs=" ".join([
        "-P batch_size=20",
        f"-P register_model_name={EXPERIMENT_NAME}_vgg16",
        "-P image_size=224,224,3",
        "-P model_architecture=vgg16",
        "-P epochs=30",
        f"-P data_dir_training={DATASET_DIR}/Training",
        f"-P data_dir_testing={DATASET_DIR}/Test",
    ]),
    queue="tensorflow_gpu",
    timeout="1h",
)

print("Training job for VGG16 neural network submitted")
print("")
pprint.pprint(response_vgg16_train)

Training job for VGG16 neural network submitted

{'createdOn': '2021-07-15T05:20:17.248335',
 'dependsOn': None,
 'entryPoint': 'train',
 'entryPointKwargs': '-P batch_size=20 -P '
                     'register_model_name=howard_fruits360_adversarial_patches_vgg16 '
                     '-P image_size=224,224,3 -P model_architecture=vgg16 -P '
                     'epochs=30 -P '
                     'data_dir_training=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Training '
                     '-P '
                     'data_dir_testing=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Test',
 'experimentId': 11,
 'jobId': '0c47a77d-ec32-4905-9b25-ce222a498995',
 'lastModified': '2021-07-15T05:20:17.248335',
 'mlflowRunId': None,
 'queueId': 2,
 'status': 'queued',
 'timeout': '1h',
 'workflowUri': 's3://workflow/dbb6336d7eb0400bbca74498d3284ee5/workflows.tar.gz'}


The following helper functions will recheck the job responses until the job is completed or a run ID is available. 
The run ID is needed to link dependencies between jobs.

In [9]:
def mlflow_run_id_is_not_known(job_response):
    return job_response["mlflowRunId"] is None and job_response["status"] not in [
        "failed",
        "finished",
    ]


def get_run_id(job_response):
    while mlflow_run_id_is_not_known(job_response):
        time.sleep(1)
        job_response = restapi_client.get_job_by_id(job_response["jobId"])
        
    return job_response


def wait_until_finished(job_response):
    # First make sure job has started.
    job_response = get_run_id(job_response)
    
    # Next re-check job until it has stopped running.
    while (job_response["status"] not in ["failed", "finished"]):
        time.sleep(1)
        job_response = restapi_client.get_job_by_id(job_response["jobId"])
    
    return job_response    

Now wait for the job to complete before proceeding to next steps.

In [10]:
response_vgg16_train = wait_until_finished(response_vgg16_train)
print("Training job for VGG16 neural network")
pprint.pprint(response_vgg16_train)

Training job for VGG16 neural network
{'createdOn': '2021-07-15T05:20:17.248335',
 'dependsOn': None,
 'entryPoint': 'train',
 'entryPointKwargs': '-P batch_size=20 -P '
                     'register_model_name=howard_fruits360_adversarial_patches_vgg16 '
                     '-P image_size=224,224,3 -P model_architecture=vgg16 -P '
                     'epochs=30 -P '
                     'data_dir_training=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Training '
                     '-P '
                     'data_dir_testing=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Test',
 'experimentId': 11,
 'jobId': '0c47a77d-ec32-4905-9b25-ce222a498995',
 'lastModified': '2021-07-15T06:08:44.012223',
 'mlflowRunId': '3973b591d6d6435884a5fdad4ef3bad8',
 'queueId': 2,
 'status': 'finished',
 'timeout': '1h',
 'workflowUri': 's3://workflow/dbb6336d7eb0400bbca74498d3284ee5/workflows.tar.gz'}


## Checking baseline VGG16 job accuracy

Once the job has finished running we can view the results either through the MLflow URI or by accessing the job via MLflow client.
Here we will show the baseline accuracy results from the previous training job.
Please see [Querying the MLFlow Tracking Service](#Querying-the-MLFlow-Tracking-Service) section for more details.

In [11]:
# Helper function for viewing MLflow results.
def get_mlflow_results(job_response):
    mlflow_client = MlflowClient()
    job_response = wait_until_finished(job_response)
    
    if(job_response['status']=="failed"):
        return {}
    
    run = mlflow_client.get_run(job_response["mlflowRunId"])  
    
    while(len(run.data.metrics) == 0):
        time.sleep(1)
        run = mlflow_client.get_run(job_response["mlflowRunId"])
        
    return run


results = get_mlflow_results(response_vgg16_train)
pprint.pprint(results.data.metrics)

{'accuracy': 0.998389482498169,
 'auc': 0.9999687671661377,
 'loss': 0.005382790860035705,
 'precision': 0.9986368417739868,
 'recall': 0.9983274936676025,
 'restored_epoch': 9.0,
 'stopped_epoch': 14.0,
 'training_time_in_minutes': 40.69016091666666,
 'val_accuracy': 0.9859119653701782,
 'val_auc': 0.9994112849235535,
 'val_loss': 0.04541686677971514,
 'val_precision': 0.9875311851501465,
 'val_recall': 0.9845032095909119}


## Deploying and Testing Adversarial Patches

Now we will create and apply the adversarial patches over our test set and evaluate the performance of the baseline model on the adversarial patches.
We will also apply the patches over the training set for the adversarial training defense evaluation.

### Patch Generation

The following job will generate the adversarial patches. 
Feel free to adjust the input parameters to see how they impact the effectiveness of the patch attack.

In [12]:
# Create Patches
response_vgg16_patches = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="gen_patch",
    entry_point_kwargs=" ".join(
        [
            f"-P model_name={EXPERIMENT_NAME}_vgg16",
            f"-P model_version=none",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            f"-P data_dir={DATASET_DIR}/Training",
            "-P num_patch_gen_samples=20",
            "-P num_patch=1",
            "-P patch_target=5"
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_vgg16_train["jobId"],
)

print("Patch attack (VGG16 architecture) job submitted")
print("")
pprint.pprint(response_vgg16_patches)
print("")

response_vgg16_patches = get_run_id(response_vgg16_patches)

Patch attack (VGG16 architecture) job submitted

{'createdOn': '2021-07-15T06:08:44.797105',
 'dependsOn': '0c47a77d-ec32-4905-9b25-ce222a498995',
 'entryPoint': 'gen_patch',
 'entryPointKwargs': '-P model_name=howard_fruits360_adversarial_patches_vgg16 '
                     '-P model_version=none -P image_size=224,224,3 -P '
                     'imagenet_preprocessing=True -P '
                     'data_dir=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Training '
                     '-P num_patch_gen_samples=20 -P num_patch=1 -P '
                     'patch_target=5',
 'experimentId': 11,
 'jobId': 'd2c9a07b-5867-4327-b73b-3a750848139e',
 'lastModified': '2021-07-15T06:08:44.797105',
 'mlflowRunId': None,
 'queueId': 2,
 'status': 'queued',
 'timeout': '24h',
 'workflowUri': 's3://workflow/77a60433a64544abaaa3ac084dbf07a4/workflows.tar.gz'}



### Deploying and Testing Adversarial Patches

Now we will apply the adversarial patches over our test set and evaluate the performance of the baseline model on the adversarial patches.

In [13]:
# Deploy Patch attack on training set.
response_deploy_vgg16_patches_training = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="deploy_patch",
    entry_point_kwargs=" ".join(
        [
            f"-P run_id={response_vgg16_patches['mlflowRunId']}",
            f"-P model_name={EXPERIMENT_NAME}_vgg16",
            f"-P model_version=none",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            f"-P data_dir={DATASET_DIR}/Training",
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_vgg16_patches["jobId"],
)

print("Patch deployment (VGG16 architecture) job submitted")
print("")
pprint.pprint(response_deploy_vgg16_patches_training)
print("")

response_deploy_vgg16_patches_training = get_run_id(response_deploy_vgg16_patches_training)

    
# Deploy Patch attack on test set.
response_deploy_vgg16_patches_testing = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="deploy_patch",
    entry_point_kwargs=" ".join(
        [
            f"-P run_id={response_vgg16_patches['mlflowRunId']}",
            f"-P model_name={EXPERIMENT_NAME}_vgg16",
            f"-P model_version=none",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            f"-P data_dir={DATASET_DIR}/Test",
            "-P patch_deployment_method=corrupt"
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_vgg16_patches["jobId"],
)

print("Patch deployment (VGG16 architecture) job submitted")
print("")
pprint.pprint(response_deploy_vgg16_patches_testing)
print("")

response_deploy_vgg16_patches_testing = get_run_id(response_deploy_vgg16_patches_testing)

Patch deployment (VGG16 architecture) job submitted

{'createdOn': '2021-07-15T06:08:51.985005',
 'dependsOn': 'd2c9a07b-5867-4327-b73b-3a750848139e',
 'entryPoint': 'deploy_patch',
 'entryPointKwargs': '-P run_id=46d0ebeb55c04a59a52f5f05756c6664 -P '
                     'model_name=howard_fruits360_adversarial_patches_vgg16 -P '
                     'model_version=none -P image_size=224,224,3 -P '
                     'imagenet_preprocessing=True -P '
                     'data_dir=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Training',
 'experimentId': 11,
 'jobId': '8a0ec3a3-1379-4a2b-9c95-3c8bbb91e58e',
 'lastModified': '2021-07-15T06:08:51.985005',
 'mlflowRunId': None,
 'queueId': 2,
 'status': 'queued',
 'timeout': '24h',
 'workflowUri': 's3://workflow/d27618fe14cf4d20b60c6e526f7fc906/workflows.tar.gz'}

Patch deployment (VGG16 architecture) job submitted

{'createdOn': '2021-07-15T06:21:47.720187',
 'dependsOn': 'd2c9a07b-5867-4327-b73b-3a750848139e',
 'entryPoint': 'deploy_patc

## Patch Attack Evaluation: Baseline VGG16 Model

Now we will run an inference step to check the patch-attacked dataset with our VGG16-trained model.

In [14]:
# Check patched dataset results   
response_infer_vgg16_patch = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="infer",
    entry_point_kwargs=" ".join(
        [
            f"-P run_id={response_deploy_vgg16_patches_testing['mlflowRunId']}",
            f"-P model_name={EXPERIMENT_NAME}_vgg16",
            f"-P model_version=none",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            "-P adv_tar_name=adversarial_patch_dataset.tar.gz",
            "-P adv_data_dir=adv_patch_dataset",
            "-P batch_size=512",
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_deploy_vgg16_patches_testing["jobId"],
)

print("Patch evaluation (VGG16 architecture) job submitted")
print("")
pprint.pprint(response_infer_vgg16_patch)
print("")

Patch evaluation (VGG16 architecture) job submitted

{'createdOn': '2021-07-15T06:21:54.898392',
 'dependsOn': '4e59dd93-7b45-4569-82a9-d9794def12b3',
 'entryPoint': 'infer',
 'entryPointKwargs': '-P run_id=61f3e4accc954ad1b11702631cc268ec -P '
                     'model_name=howard_fruits360_adversarial_patches_vgg16 -P '
                     'model_version=none -P image_size=224,224,3 -P '
                     'imagenet_preprocessing=True -P '
                     'adv_tar_name=adversarial_patch_dataset.tar.gz -P '
                     'adv_data_dir=adv_patch_dataset -P batch_size=512',
 'experimentId': 11,
 'jobId': '7bcb57e6-045f-41ef-805d-c981e71eb28b',
 'lastModified': '2021-07-15T06:21:54.898392',
 'mlflowRunId': None,
 'queueId': 2,
 'status': 'queued',
 'timeout': '24h',
 'workflowUri': 's3://workflow/547cd9110c104adaad3c3438248db601/workflows.tar.gz'}



In [15]:
# Wait for the job to finish
response_infer_vgg16_patch = wait_until_finished(response_infer_vgg16_patch)

# Check on the patch evaluation results
results = get_mlflow_results(response_infer_vgg16_patch)
print("Baseline model results on adversarially patched dataset: ")
pprint.pprint(results.data.metrics)

Baseline model results on adversarially patched dataset: 
{'accuracy': 0.016401397064328194,
 'auc': 0.5041510462760925,
 'loss': 2224.942257764863,
 'precision': 0.016401397064328194,
 'recall': 0.016401397064328194}



We can see that the adversarial patch attack causes a noticeable decrease in the model's accuracy scores.

We will now test various defenses against the patch attacked images.

# Defense: Adversarial Training

The next part of the adversarial patch demo focuses on investigating effective defenses against the attack.

### Adversarial Training Defense

We will train a new copy of the VGG16 model on training set that contains adversarial patches.
In doing so, the model learns to ignore the adversarial patches.

In [None]:
response_patches_adv_training = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="train",
    entry_point_kwargs=" ".join(
        [
            f"-P dataset_run_id_testing={response_deploy_vgg16_patches_testing['mlflowRunId']}",
            f"-P dataset_run_id_training={response_deploy_vgg16_patches_training['mlflowRunId']}",
            "-P batch_size=256",
            f"-P register_model_name={EXPERIMENT_NAME}_vgg16",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            "-P epochs=10",
            f"-P data_dir_training={DATASET_DIR}/Training",
            f"-P data_dir_testing={DATASET_DIR}/Test",
            "-P load_dataset_from_mlruns=True",
            
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_deploy_vgg16_patches_training["jobId"],
)

print("Patch adversarial training (VGG16 architecture) job submitted")
print("")
pprint.pprint(response_patches_adv_training)
print("")

response_patches_adv_training = get_run_id(response_patches_adv_training)

Patch adversarial training (VGG16 architecture) job submitted

{'createdOn': '2021-07-15T06:55:47.483363',
 'dependsOn': '8a0ec3a3-1379-4a2b-9c95-3c8bbb91e58e',
 'entryPoint': 'train',
 'entryPointKwargs': '-P '
                     'dataset_run_id_testing=61f3e4accc954ad1b11702631cc268ec '
                     '-P '
                     'dataset_run_id_training=2729622707694481a4645a5c46a9dbe6 '
                     '-P batch_size=256 -P '
                     'register_model_name=howard_fruits360_adversarial_patches_vgg16 '
                     '-P image_size=224,224,3 -P imagenet_preprocessing=True '
                     '-P epochs=10 -P '
                     'data_dir_training=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Training '
                     '-P '
                     'data_dir_testing=/nfs/data/Fruits360-Kaggle-2019/fruits-360/Test '
                     '-P load_dataset_from_mlruns=True',
 'experimentId': 11,
 'jobId': 'bc83dcba-f500-47c3-8866-d07fc87ba343',
 'lastModif

In [None]:
response_evaluate_adv_training = restapi_client.submit_job(
    workflows_file=WORKFLOWS_TAR_GZ,
    experiment_name=EXPERIMENT_NAME,
    entry_point="infer",
    entry_point_kwargs=" ".join(
        [
            f"-P run_id={response_deploy_vgg16_patches_testing['mlflowRunId']}",
            f"-P model_name={EXPERIMENT_NAME}_adversarial_patch_vgg16",
            f"-P model_version=none",
            "-P image_size=224,224,3",
            "-P imagenet_preprocessing=True",
            "-P batch_size=256",
            "-P adv_tar_name=adversarial_patch_dataset.tar.gz",
            "-P adv_data_dir=adv_patch_dataset",
        ]
    ),
    queue="tensorflow_gpu",
    depends_on=response_patches_adv_training["jobId"],
)

print("Patch evaluation job submitted")
print("")
pprint.pprint(response_evaluate_adv_training)
print("")

response_patches_adv_training= wait_until_finished(response_evaluate_adv_training)
results = get_mlflow_results(response_patches_adv_training)
print("Adversarial Training Results:")
pprint.pprint(results.data.metrics)

## Querying the MLFlow Tracking Service

Currently the lab API can only be used to register experiments and start jobs, so if users wish to extract their results programmatically, they can use the `MlflowClient()` class from the `mlflow` Python package to connect and query their results.
Since we captured the run ids generated by MLFlow, we can easily retrieve the data logged about one of our jobs and inspect the results.
To start the client, we simply need to run,

In [None]:
mlflow_client = MlflowClient()

The client uses the environment variable `MLFLOW_TRACKING_URI` to figure out how to connect to the MLFlow Tracking Service, which we configured near the top of this notebook.
To query the results of one of our runs, we just need to pass the run id to the client's `get_run()` method.
As an example, let's query the run results for the patch attack applied to the VGG16 architecture,

In [None]:
run_adv_patches = mlflow_client.get_run(response_patches_adv_training["mlflowRunId"])

If the request completed successfully, we should now be able to query data collected during the run.
For example, to review the collected metrics, we just use,

In [None]:
pprint.pprint(run_adv_patches.data.metrics)

To review the run's parameters, we use,

In [None]:
pprint.pprint(run_adv_patches.data.params)

To review the run's tags, we use,

In [None]:
pprint.pprint(run_adv_patches.data.tags)

There are many things you can query using the MLFlow client.
[The MLFlow documentation gives a full overview of the methods that are available](https://www.mlflow.org/docs/latest/python_api/mlflow.tracking.html#mlflow.tracking.MlflowClient).