You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello, your job is great! I am confused about one point. If one image could not be perturbed successfully by attacker A, it would be perturbed by attacker B. Then I have a question, attacker B would perturb the original image or the perturbed image by attacker A?
The text was updated successfully, but these errors were encountered:
Hello, I use the autoattack with standard and non-individual version. It outputs four robust accuracies under four attacks. Which robust accuracy should I choose at last as the evaluation of the model?
if you're using run_standard_evaluation you should take the last one, which includes all attacks. If instead you use run_standard_evaluation_individual you need to compute the worst-case over the different methods manually.
Hello, your job is great! I am confused about one point. If one image could not be perturbed successfully by attacker A, it would be perturbed by attacker B. Then I have a question, attacker B would perturb the original image or the perturbed image by attacker A?
The text was updated successfully, but these errors were encountered: