-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathlocalmain.py
67 lines (59 loc) · 2.69 KB
/
localmain.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
import numpy as np
from foolbox2.criteria import TargetClass
from foolbox2.models.wrappers import CompositeModel
from fmodel import create_fmodel
from foolbox2.attacks.iterative_projected_gradient import MomentumIterativeAttack
from foolbox2.distances import MeanSquaredDistance
from foolbox2.adversarial import Adversarial
# from adversarial_vision_challenge import load_model
# from adversarial_vision_challenge import read_images
# from adversarial_vision_challenge import store_adversarial
# from adversarial_vision_challenge import attack_complete
from iterative import SAIterativeAttack, RMSIterativeAttack, AdamIterativeAttack, AdagradIterativeAttack
import os, csv
from scipy.misc import imread, imsave
import PIL.Image
def run_attack(model, image, target_class):
criterion = TargetClass(target_class)
# model == Composite model
# Backward model = substitute model (resnet vgg alex) used to calculate gradients
# Forward model = black-box model
# distance = MeanSquaredDistance
attack = RMSIterativeAttack(model, criterion)
# attack = foolbox.attacks.annealer(model, criterion)
# prediction of our black box model on the original image
original_label = np.argmax(model.predictions(image))
# adv = Adversarial(model, criterion, image, original_label, distance=distance)
# return attack(adv)
return attack(image, model_path = None, label = original_label)
def main():
# instantiate blackbox and substitute model
forward_model = load_model()
backward_model = create_fmodel()
# instantiate differntiable composite model
# (predictions from blackbox, gradients from substitute)
model = CompositeModel(
forward_model=forward_model,
backward_model=backward_model)
for (file_name, image, label) in read_images():
adversarial = run_attack(model, image, label)
store_adversarial(file_name, adversarial)
# Announce that the attack is complete
# NOTE: In the absence of this call, your submission will timeout
# while being graded.
attack_complete()
def read_images():
data_dir = os.path.join(os.path.dirname(os.path.realpath(__file__)), "flower")
with open(os.path.join(data_dir, "target_class.csv")) as csvfile:
reader = csv.reader(csvfile)
for row in reader:
yield (row[0], np.array(PIL.Image.open(os.path.join(data_dir, row[1])).convert("RGB")), int(row[2]))
def attack_complete():
pass
def store_adversarial(file_name, adversarial):
out_dir = os.path.join(os.path.dirname(os.path.realpath(__file__)), "output")
imsave(os.path.join(out_dir, file_name + ".png"), adversarial, format="png")
def load_model():
return create_fmodel()
if __name__ == '__main__':
main()