SYNTOLOGY HomeExplorerAtlasCodeMethodologyAboutDevelopersFeedPricing
Paper · 1711.00851 · 2017

Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope

J Zico Kolter, Eric Wong

arXiv · PDF · Open in the Atlas

Code that ran

We lifted 44 functions out of this paper's own repositories and ran 21 of them in a sandbox. "Ran" means the function executed on a synthesized input and returned a value. It is not a reproduction of the paper's results.

FunctionStatusWhere it lives
Conv2dUntiedBias Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("9634a2860dbe32ed")
DualLinear Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("a465ad16a8510751")
DualReLU Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("4d488a7c833e637b")
DualReLUProj Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("733e1d54c3d21ea9")
DualReLUProj Ran Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("a721c225e4045355")
DualReshape Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("d1e8d479da8d224c")
Identity Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("15451c00600189d1")
InfBall Ran Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("7b3dd3557f3b683e")
InfBall Ran locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("a31183fb505bf309")
InfBallBounded Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("0607bcee1940ecc6")
InfBallBounded Ran locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("37ea0914d3143c9f")
InfBallProj Ran Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("d0f7cdcc96ab6561")
InfBallProj Ran locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("49cb906dccd76915")
InfBallProjBounded Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("9568161abd5fcecf")
InfBallProjBounded Ran Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("341ef71271a4cbef")
InfBallProjBounded Ran locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("5a79e42b5ecc22cd")
L2Ball Ran Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("006a937f9cba3174")
batch Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("778274b3fb463e7e")
full_bias Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("2a4b1b5d869483b9")
get_layer_bound_relax_adaptive_matrix_huan_optimized Ran huanzhang12/CROWN-Robustness-Certification/get_bounds_ours.py
pointer only (licence: NOASSERTION) · get_code("728154bbcd429f2b")
unbatch Ran fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("9efb427bc4cdf3df")
AditiMNIST Not yet run ermongroup/generative_adversary/models/aditi_mnist.py
pointer only (licence: GPL-3.0) · get_code("f301dfa41009abd3")
Dense Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("bc7271d7a6811f02")
DenseSequential Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("18133b07da9a458e")
DualBatchNorm2d Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("c52d8aff384b08a4")
DualConv2d Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("b23673a5bc8ae4a6")
DualConv2d Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("3d025a7e72e695af")
DualDense Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("d11e9d2b6bc1c8a7")
DualDense Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("5428007ec654a464")
DualLayer Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("46dfb83f015faad4")
DualNetwork Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("2f26c3676bd1d6ca")
DualNetwork Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("d09a9fa8766395b6")
DualNetwork Not yet run locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("34e633f7b59f06cd")
DualObject Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("7e8fbd57df2c528e")
InfBall Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("0b1a6f38f8307d1f")
InfBallProj Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("edc9bd1055691c58")
L2BallProj Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("610e37ee41f7c916")
conv2d Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("26c63c3b5b5c6239")
conv_transpose2d Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("73dd3a4a0039021b")
select_input Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("4fb58a8213bd4638")
select_input Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("935601b807dbd64e")
select_input Not yet run locuslab/convex_adversarial/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("5187a83994dc73d4")
select_layer Not yet run fra31/mmr-universal/kolter_wong/convex_adversarial/dual_network.py
code served (permissive licence) · get_code("822d6e0702879c11")
select_layer Not yet run Hadisalman/robust-verify-benchmark/wong_kolter/dual_network.py
code served (permissive licence) · get_code("96d6186dbe64fc7e")

Repositories linked to this paper

Some links come from the archived Papers with Code dataset (CC BY-SA 4.0): attribution and licence.

Abstract

We propose a method to learn deep ReLU-based classifiers that are provably robust against normbounded adversarial perturbations on the training data. For previously unseen examples, the approach is guaranteed to detect all adversarial examples, though it may flag some non-adversarial examples as well. The basic idea is to consider a convex outer approximation of the set of activations reachable through a norm-bounded perturbation, and we develop a robust optimization procedure that minimizes the worst case loss over this outer region (via a linear program). Crucially, we show that the dual problem to this linear program can be represented itself as a deep network similar to the backpropagation network, leading to very efficient optimization approaches that produce guaranteed bounds on the robust loss. The end result is that by executing a few more forward and backward passes through a slightly modified version of the original network (though possibly with much larger batch sizes), we can learn a classifier that is provably robust to any norm-bounded adversarial attack. We illustrate the approach on a number of tasks to train classifiers with robust adversarial guarantees (e.g. for MNIST, we produce a convolutional classifier that provably has less than 5.8% test error for any adversarial attack with bounded ∞ norm less than = 0.1), and code for all experiments is available at http://github.com/ locuslab/convex_adversarial.

For agents

The same record, over MCP at https://syntology.ai/mcp:

get_harvested_code_for_paper("1711.00851")
get_code_for_paper("1711.00851")
have("1711.00851")

Connect an agent — have() is free.