├── .gitignore ├── ml-basics └── mnist │ ├── README.md │ ├── mnist-loading-basic-steps.ipynb │ ├── mnist-incorrect-and-abiguous-labels.ipynb │ └── mnist.ipynb ├── examples ├── adversarial-examples │ ├── lion.jpg │ ├── ostrich.jpg │ ├── adversarial_example.ipynb │ ├── adversarial_examples.md │ └── imagenet_class_index.json ├── inversion-attack │ └── att-database-of-faces.zip ├── model-stealing │ └── model_stealing_logistic_regression.ipynb └── backdoors │ └── mnist.ipynb ├── LICENSE ├── requirements.txt ├── README.md └── inversion.ipynb /.gitignore: -------------------------------------------------------------------------------- 1 | .ipynb_checkpoints/ 2 | .data 3 | venv 4 | -------------------------------------------------------------------------------- /ml-basics/mnist/README.md: -------------------------------------------------------------------------------- 1 | # INSTALL 2 | 3 | pip install torch torchvision matplotlib -------------------------------------------------------------------------------- /examples/adversarial-examples/lion.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/daniel-e/secml/HEAD/examples/adversarial-examples/lion.jpg -------------------------------------------------------------------------------- /examples/adversarial-examples/ostrich.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/daniel-e/secml/HEAD/examples/adversarial-examples/ostrich.jpg -------------------------------------------------------------------------------- /examples/inversion-attack/att-database-of-faces.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/daniel-e/secml/HEAD/examples/inversion-attack/att-database-of-faces.zip -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | MIT License 2 | 3 | Copyright (c) 2018 4 | 5 | Permission is hereby granted, free of charge, to any person obtaining a copy 6 | of this software and associated documentation files (the "Software"), to deal 7 | in the Software without restriction, including without limitation the rights 8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell 9 | copies of the Software, and to permit persons to whom the Software is 10 | furnished to do so, subject to the following conditions: 11 | 12 | The above copyright notice and this permission notice shall be included in all 13 | copies or substantial portions of the Software. 14 | 15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE 18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, 20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 21 | SOFTWARE. 22 | -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- 1 | attrs==19.1.0 2 | backcall==0.1.0 3 | bleach==3.3.0 4 | cycler==0.10.0 5 | decorator==4.4.0 6 | defusedxml==0.6.0 7 | entrypoints==0.3 8 | ipykernel==5.1.1 9 | ipython==8.10.0 10 | ipython-genutils==0.2.0 11 | ipywidgets==7.4.2 12 | jedi==0.14.0 13 | Jinja2==2.11.3 14 | jsonschema==3.0.1 15 | jupyter==1.0.0 16 | jupyter-client==5.2.4 17 | jupyter-console==6.0.0 18 | jupyter-core==4.11.2 19 | kiwisolver==1.1.0 20 | MarkupSafe==1.1.1 21 | matplotlib==3.1.0 22 | mistune==2.0.3 23 | nbconvert==6.5.1 24 | nbformat==4.4.0 25 | notebook==6.4.12 26 | numpy==1.22.0 27 | pandocfilters==1.4.2 28 | parso==0.5.0 29 | pexpect==4.7.0 30 | pickleshare==0.7.5 31 | Pillow==9.0.1 32 | pkg-resources==0.0.0 33 | prometheus-client==0.7.1 34 | prompt-toolkit==2.0.9 35 | ptyprocess==0.6.0 36 | Pygments==2.7.4 37 | pyparsing==2.4.0 38 | pyrsistent==0.15.2 39 | python-dateutil==2.8.0 40 | pyzmq==18.0.1 41 | qtconsole==4.5.1 42 | Send2Trash==1.5.0 43 | six==1.12.0 44 | terminado==0.8.2 45 | testpath==0.4.2 46 | torch==1.13.1 47 | torchvision==0.3.0 48 | tornado==6.0.3 49 | tqdm==4.32.2 50 | traitlets==4.3.2 51 | wcwidth==0.1.7 52 | webencodings==0.5.1 53 | widgetsnbextension==3.4.2 54 | -------------------------------------------------------------------------------- /ml-basics/mnist/mnist-loading-basic-steps.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "markdown", 5 | "metadata": {}, 6 | "source": [ 7 | "# Loading MNIST Digits in Batches With PyTorch" 8 | ] 9 | }, 10 | { 11 | "cell_type": "code", 12 | "execution_count": null, 13 | "metadata": {}, 14 | "outputs": [], 15 | "source": [ 16 | "from torch import utils\n", 17 | "from torchvision import datasets, transforms\n", 18 | "\n", 19 | "# Transform PIL image into a tensor. The values are in the range [0, 1]\n", 20 | "t = transforms.ToTensor()\n", 21 | "\n", 22 | "# Load datasets for training and apply the given transformation.\n", 23 | "mnist = datasets.MNIST(root='data', train=True, download=True, transform=t)\n", 24 | "\n", 25 | "# Specify a data loader which returns 500 examples in each iteration.\n", 26 | "n = 500\n", 27 | "loader = utils.data.DataLoader(mnist, batch_size=n, shuffle=True)\n", 28 | "\n", 29 | "# Iterate over the batches.\n", 30 | "for imgs, labels in loader:\n", 31 | " # do something" 32 | ] 33 | } 34 | ], 35 | "metadata": { 36 | "interpreter": { 37 | "hash": "3c31154c2e6d078d13498c87eb48ca372ee3ad3d9153e56081b43cdb07df7cf4" 38 | }, 39 | "kernelspec": { 40 | "display_name": "Python 3.8.10 64-bit ('venv': venv)", 41 | "language": "python", 42 | "name": "python3" 43 | }, 44 | "language_info": { 45 | "codemirror_mode": { 46 | "name": "ipython", 47 | "version": 3 48 | }, 49 | "file_extension": ".py", 50 | "mimetype": "text/x-python", 51 | "name": "python", 52 | "nbconvert_exporter": "python", 53 | "pygments_lexer": "ipython3", 54 | "version": "3.8.10" 55 | }, 56 | "orig_nbformat": 4 57 | }, 58 | "nbformat": 4, 59 | "nbformat_minor": 2 60 | } 61 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Introduction 2 | 3 | Like software systems also machine learning can suffer from security weaknesses. This repository contains some resources to provide an overview. 4 | 5 | ## Possible Security Issues in Machine Learning 6 | 7 | ### Poisoning 8 | 9 | In a poisoning attack an adversary can insert carefully crafted examples into the training data. Hence, this attack happens at training time. First, such an attack could degrade the performance of a machine learning model (the adversary targets the availability of the model). Second, the adversary could use this technique to inject a backdoor. 10 | 11 | #### Resources 12 | 13 | * [Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning](https://arxiv.org/pdf/1712.05526), 2017 14 | * [Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning](https://arxiv.org/pdf/1804.00308.pdf), 2018 15 | * [Data poisoning attacks against online learning](https://arxiv.org/abs/1808.08994), 2018 16 | * [Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks](https://arxiv.org/abs/1809.02861), 2018 17 | 18 | ### Evasion 19 | 20 | An evasion attack happens at test time. Here, an instance that would be classified correctly without modification, will be misclassified when small modifications are added by the adversary. A well know example of evasion attacks are adversarial examples. An adversary adds small perturbations to an image which are invisible to a human but will fool the image classifier which will misclassify them into a category that can be chosen by the adversary. 21 | 22 | #### Resources 23 | 24 | * [Intriguing properties of neural networks](https://arxiv.org/abs/1312.6199), 2014 25 | * [Explaining and Harnessing Adversarial Examples](https://arxiv.org/abs/1412.6572), 2014 26 | * [Evasion Attacks against Machine Learning at Test Time](https://arxiv.org/abs/1708.06131), 2017 27 | * [Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods](https://arxiv.org/abs/1705.07263), 2017 28 | 29 | ### Inversion Attacks 30 | 31 | In inversion attacks an adversary tries to extract useful information from a machine learning model like training data that was used for the training. Due to the fact that machine learning is used in more and more privacy sensitive applications an adversary could learn very sensitive data of individuals. 32 | 33 | #### Resources 34 | 35 | * [Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing](https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-fredrikson-privacy.pdf), 2014 36 | * [Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures](https://www.cs.cmu.edu/~mfredrik/papers/fjr2015ccs.pdf), 2015 37 | * [Membership Model Inversion Attacks for Deep Networks](https://arxiv.org/abs/1910.04257), 2019 38 | * [The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks](https://arxiv.org/abs/1911.07135), 2019 39 | 40 | # Examples 41 | 42 | This repositories contains some examples of attacks in the folder `example`. Examples are: 43 | 44 | * Create adversarial examples 45 | * Model stealing 46 | * Model inversion attacks 47 | 48 | To run the examples it is recommended to create a virtual environment first and install all required packages in that environment: 49 | 50 | virtualenv -p python3 venv 51 | source venv/bin/activate 52 | pip3 install -r requirements.txt 53 | 54 | # Resources 55 | 56 | * [TensorFlow Privacy](https://github.com/tensorflow/privacy) 57 | * [PySyft](https://github.com/OpenMined/PySyft) 58 | * [Encrypted Training Demo on MNIST](https://blog.openmined.org/encrypted-training-on-mnist/) 59 | 60 | -------------------------------------------------------------------------------- /inversion.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "code", 5 | "execution_count": null, 6 | "metadata": {}, 7 | "outputs": [], 8 | "source": [ 9 | "import torch\n", 10 | "import torchvision as tv\n", 11 | "import matplotlib.pyplot as plt\n", 12 | "from PIL import Image\n", 13 | "import numpy as np" 14 | ] 15 | }, 16 | { 17 | "cell_type": "code", 18 | "execution_count": null, 19 | "metadata": {}, 20 | "outputs": [], 21 | "source": [ 22 | "%%bash\n", 23 | "\n", 24 | "rm -rf .data\n", 25 | "mkdir .data\n", 26 | "unzip -q att-database-of-faces.zip -d .data/faces-training\n", 27 | "cp -a .data/faces-training .data/faces-test\n", 28 | "\n", 29 | "rm .data/faces-training/*/{1,2,3,4,5}.pgm\n", 30 | "rm .data/faces-test/*/{6,7,8,9,10}.pgm" 31 | ] 32 | }, 33 | { 34 | "cell_type": "code", 35 | "execution_count": null, 36 | "metadata": {}, 37 | "outputs": [], 38 | "source": [ 39 | "torch.manual_seed(1)\n", 40 | "\n", 41 | "t = tv.transforms.Compose([\n", 42 | " tv.transforms.Grayscale(),\n", 43 | " tv.transforms.ToTensor()\n", 44 | "])\n", 45 | "\n", 46 | "# Load AT&T database of faces.\n", 47 | "dataset = tv.datasets.ImageFolder(root=\".data/faces-training\", transform=t)\n" 48 | ] 49 | }, 50 | { 51 | "cell_type": "code", 52 | "execution_count": null, 53 | "metadata": {}, 54 | "outputs": [], 55 | "source": [ 56 | "target_person = 30\n", 57 | "\n", 58 | "all_images_of_target = [img for img, label in dataset if label == target_person]\n", 59 | "\n", 60 | "_, ax = plt.subplots(1, len(all_images_of_target), figsize=(20, 5))\n", 61 | " \n", 62 | "for p, img in zip(ax, all_images_of_target):\n", 63 | " p.imshow(img.squeeze(), cmap=\"gray\")\n", 64 | " p.axis(\"off\")\n", 65 | "\n", 66 | "plt.show()" 67 | ] 68 | }, 69 | { 70 | "cell_type": "code", 71 | "execution_count": null, 72 | "metadata": {}, 73 | "outputs": [], 74 | "source": [ 75 | "nc = 40\n", 76 | "nf = 112 * 92\n", 77 | "\n", 78 | "model = torch.nn.Linear(nf, nc)\n", 79 | "\n", 80 | "opt = torch.optim.SGD(model.parameters(), lr=0.1)\n", 81 | "\n", 82 | "criterion = torch.nn.CrossEntropyLoss()" 83 | ] 84 | }, 85 | { 86 | "cell_type": "code", 87 | "execution_count": null, 88 | "metadata": {}, 89 | "outputs": [], 90 | "source": [ 91 | "loader = torch.utils.data.DataLoader(dataset, batch_size=20, shuffle=True)\n", 92 | "\n", 93 | "n_epochs = 20\n", 94 | "cost = []\n", 95 | "\n", 96 | "for i in range(n_epochs):\n", 97 | " l = 0\n", 98 | " n = 0\n", 99 | " for img, labels in loader:\n", 100 | " img = img.view(-1, nf) # from [nbatches, 1, 112, 92] to [nbatches, 10304]\n", 101 | " output = model(img)\n", 102 | " opt.zero_grad()\n", 103 | " loss = criterion(output, labels)\n", 104 | " loss.backward()\n", 105 | "\n", 106 | " rnd = torch.distributions.normal.Normal(0.0, 1.0)\n", 107 | " for p in model.parameters():\n", 108 | " p.grad += rnd.sample(torch.Size(p.grad.shape)) * 0.3\n", 109 | " \n", 110 | " ##########################################################\n", 111 | " # Enable the following lines to get more privacy.\n", 112 | " ##########################################################\n", 113 | " #rnd = torch.distributions.normal.Normal(0.0, 1.0)\n", 114 | " #for p in model.parameters():\n", 115 | " # p.grad += rnd.sample(torch.Size(p.grad.shape)) * 0.3\n", 116 | " ##########################################################\n", 117 | " \n", 118 | " opt.step()\n", 119 | " l += loss.item()\n", 120 | " n += 1\n", 121 | " print(i, l/n)\n", 122 | " cost.append(l/n)\n", 123 | " \n", 124 | "plt.plot(cost)\n", 125 | "plt.show()" 126 | ] 127 | }, 128 | { 129 | "cell_type": "code", 130 | "execution_count": null, 131 | "metadata": {}, 132 | "outputs": [], 133 | "source": [ 134 | "dataset = tv.datasets.ImageFolder(root=\".data/faces-test\", transform=t)\n", 135 | "test_loader = torch.utils.data.DataLoader(dataset, batch_size=200)\n", 136 | "\n", 137 | "with torch.no_grad():\n", 138 | " img, labels = iter(test_loader).next()\n", 139 | " r = model(img.view(-1, nf))\n", 140 | " p = r.argmax(dim=1)\n", 141 | " print(\"images:\", len(labels))\n", 142 | " print(\"accuracy:\", (labels == p).sum().item() / len(labels))\n" 143 | ] 144 | }, 145 | { 146 | "cell_type": "code", 147 | "execution_count": null, 148 | "metadata": {}, 149 | "outputs": [], 150 | "source": [ 151 | "import torch.nn.functional as F\n", 152 | "\n", 153 | "x = torch.zeros(nf, requires_grad=True)\n", 154 | "o = torch.optim.SGD([x], lr=0.1)\n", 155 | "\n", 156 | "for i in range(1000):\n", 157 | " scores = F.softmax(model(x.view(1, nf)), dim=1).squeeze()\n", 158 | " e = torch.tensor([1.0]) - scores[target_person] # error for the target label\n", 159 | " o.zero_grad()\n", 160 | " e.backward()\n", 161 | " o.step()\n", 162 | " \n", 163 | "x" 164 | ] 165 | }, 166 | { 167 | "cell_type": "code", 168 | "execution_count": null, 169 | "metadata": {}, 170 | "outputs": [], 171 | "source": [ 172 | "r = F.softmax(model(x), dim=0)\n", 173 | "print(\"score of target person:\", r[target_person].item())\n", 174 | "print(\"scores:\")\n", 175 | "r" 176 | ] 177 | }, 178 | { 179 | "cell_type": "code", 180 | "execution_count": null, 181 | "metadata": {}, 182 | "outputs": [], 183 | "source": [ 184 | "img = x.view(112, 92).detach()\n", 185 | "\n", 186 | "plt.imshow(img, cmap=\"gray\")\n", 187 | "plt.show()" 188 | ] 189 | } 190 | ], 191 | "metadata": { 192 | "kernelspec": { 193 | "display_name": "Python 3", 194 | "language": "python", 195 | "name": "python3" 196 | }, 197 | "language_info": { 198 | "codemirror_mode": { 199 | "name": "ipython", 200 | "version": 3 201 | }, 202 | "file_extension": ".py", 203 | "mimetype": "text/x-python", 204 | "name": "python", 205 | "nbconvert_exporter": "python", 206 | "pygments_lexer": "ipython3", 207 | "version": "3.6.9" 208 | } 209 | }, 210 | "nbformat": 4, 211 | "nbformat_minor": 2 212 | } 213 | -------------------------------------------------------------------------------- /examples/model-stealing/model_stealing_logistic_regression.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "code", 5 | "execution_count": null, 6 | "metadata": {}, 7 | "outputs": [], 8 | "source": [ 9 | "import torch\n", 10 | "import torchvision.datasets as ds\n", 11 | "import torchvision.transforms as transforms" 12 | ] 13 | }, 14 | { 15 | "cell_type": "code", 16 | "execution_count": null, 17 | "metadata": {}, 18 | "outputs": [], 19 | "source": [ 20 | "# Load the MNIST training dataset.\n", 21 | "# ToTensor converts PIL image to (CxHxW) in the range [0.0, 1.0].\n", 22 | "train_set = ds.MNIST(\".data\", train=True, transform=transforms.ToTensor(), download=True)" 23 | ] 24 | }, 25 | { 26 | "cell_type": "code", 27 | "execution_count": null, 28 | "metadata": {}, 29 | "outputs": [], 30 | "source": [ 31 | "# Just select examples with labels 0 or 1.\n", 32 | "X_, y_ = zip(*[i for i in train_set if i[1] < 2])" 33 | ] 34 | }, 35 | { 36 | "cell_type": "code", 37 | "execution_count": null, 38 | "metadata": {}, 39 | "outputs": [], 40 | "source": [ 41 | "import torchvision.utils as u\n", 42 | "import matplotlib.pyplot as plt\n", 43 | "import numpy as np\n", 44 | "\n", 45 | "# Plot the first 100 examples of the dataset.\n", 46 | "plt.imshow(np.transpose(u.make_grid(list(X_[:100]), 10).numpy(), (1,2,0)))\n", 47 | "plt.show()" 48 | ] 49 | }, 50 | { 51 | "cell_type": "code", 52 | "execution_count": null, 53 | "metadata": {}, 54 | "outputs": [], 55 | "source": [ 56 | "# Each image has a size of 28x28.\n", 57 | "n = 28*28\n", 58 | "\n", 59 | "# Convert lists of examples and labels to tensors.\n", 60 | "X = torch.stack(X_).view((-1, n))\n", 61 | "y = torch.tensor(y_).view(-1, 1).float()" 62 | ] 63 | }, 64 | { 65 | "cell_type": "code", 66 | "execution_count": null, 67 | "metadata": {}, 68 | "outputs": [], 69 | "source": [ 70 | "from tqdm import tqdm_notebook\n", 71 | "\n", 72 | "# Linear regression model.\n", 73 | "model = torch.nn.Linear(n, 1, bias=True)\n", 74 | "\n", 75 | "# Select a loss function.\n", 76 | "loss = torch.nn.BCELoss()\n", 77 | "\n", 78 | "# Use stochastic gradient descent as the optimizer.\n", 79 | "opt = torch.optim.SGD(model.parameters(), lr=0.01)\n", 80 | "\n", 81 | "costs = []\n", 82 | "for i in tqdm_notebook(range(1000)):\n", 83 | " # Classify the training examples.\n", 84 | " pred_y = torch.sigmoid(model(X))\n", 85 | " # Compute the loss function.\n", 86 | " l = loss(pred_y, y)\n", 87 | " costs.append(l)\n", 88 | " # Compute gradient and update the parameters.\n", 89 | " opt.zero_grad()\n", 90 | " l.backward()\n", 91 | " opt.step()" 92 | ] 93 | }, 94 | { 95 | "cell_type": "code", 96 | "execution_count": null, 97 | "metadata": {}, 98 | "outputs": [], 99 | "source": [ 100 | "# Plot learning curve, i.e. the error in each iteration.\n", 101 | "plt.plot(costs[100:])" 102 | ] 103 | }, 104 | { 105 | "cell_type": "markdown", 106 | "metadata": {}, 107 | "source": [ 108 | "# Test the model" 109 | ] 110 | }, 111 | { 112 | "cell_type": "code", 113 | "execution_count": null, 114 | "metadata": {}, 115 | "outputs": [], 116 | "source": [ 117 | "# Load test examples.\n", 118 | "test_set = ds.MNIST(\".data\", train=False, transform=transforms.ToTensor(), download=True)\n", 119 | "\n", 120 | "X_test_, y_test_ = zip(*[i for i in test_set if i[1] < 2])\n", 121 | "X_test = torch.stack(X_test_).view(-1, n)\n", 122 | "y_test = torch.tensor(y_test_).view(-1, 1).float()" 123 | ] 124 | }, 125 | { 126 | "cell_type": "code", 127 | "execution_count": null, 128 | "metadata": {}, 129 | "outputs": [], 130 | "source": [ 131 | "# Use the classifier to predict the categories for the test examples.\n", 132 | "pred_y = torch.sigmoid(model(X_test))\n", 133 | "# Convert the probabilities (i.e. [0,1] into class labels {0, 1})\n", 134 | "labels = torch.round(pred_y)" 135 | ] 136 | }, 137 | { 138 | "cell_type": "code", 139 | "execution_count": null, 140 | "metadata": {}, 141 | "outputs": [], 142 | "source": [ 143 | "# Compute the accuracy of the classifier for the test examples.\n", 144 | "torch.sum(labels == y_test).item() / y_test.size(0)" 145 | ] 146 | }, 147 | { 148 | "cell_type": "markdown", 149 | "metadata": {}, 150 | "source": [ 151 | "# Steal model parameters" 152 | ] 153 | }, 154 | { 155 | "cell_type": "code", 156 | "execution_count": null, 157 | "metadata": {}, 158 | "outputs": [], 159 | "source": [ 160 | "# We have 28*28+1 unknowns (28*28 weights + 1 bias). Therefore, \n", 161 | "# we need 28*28+1 queries (i.e. equations).\n", 162 | "k = n+1\n", 163 | "\n", 164 | "# Create k random queries.\n", 165 | "queries = torch.rand((k, n))\n", 166 | "\n", 167 | "# Use the classifier to predict the categories for the queries.\n", 168 | "output = model(queries)" 169 | ] 170 | }, 171 | { 172 | "cell_type": "code", 173 | "execution_count": null, 174 | "metadata": {}, 175 | "outputs": [], 176 | "source": [ 177 | "# Add a column with ones for the bias to the queries. Shape (k, n) → (k, n+1).\n", 178 | "q = torch.cat((queries, torch.ones((k, 1))), 1)\n", 179 | "\n", 180 | "# Convert the queries with the added column into a numpy array.\n", 181 | "a = q.data.numpy()\n", 182 | "\n", 183 | "# Convert the output of the classifier into a numpy array.\n", 184 | "b = output.data.squeeze().numpy()" 185 | ] 186 | }, 187 | { 188 | "cell_type": "code", 189 | "execution_count": null, 190 | "metadata": {}, 191 | "outputs": [], 192 | "source": [ 193 | "# Solve for the parameters.\n", 194 | "x = np.linalg.solve(a, b)" 195 | ] 196 | }, 197 | { 198 | "cell_type": "code", 199 | "execution_count": null, 200 | "metadata": {}, 201 | "outputs": [], 202 | "source": [ 203 | "# Print the first 20 recovered parameter.\n", 204 | "x[:20]" 205 | ] 206 | }, 207 | { 208 | "cell_type": "code", 209 | "execution_count": null, 210 | "metadata": {}, 211 | "outputs": [], 212 | "source": [ 213 | "# Print the first 20 parameters of the model.\n", 214 | "model.weight.squeeze().data.numpy()[:20]" 215 | ] 216 | } 217 | ], 218 | "metadata": { 219 | "kernelspec": { 220 | "display_name": "Python 3", 221 | "language": "python", 222 | "name": "python3" 223 | }, 224 | "language_info": { 225 | "codemirror_mode": { 226 | "name": "ipython", 227 | "version": 3 228 | }, 229 | "file_extension": ".py", 230 | "mimetype": "text/x-python", 231 | "name": "python", 232 | "nbconvert_exporter": "python", 233 | "pygments_lexer": "ipython3", 234 | "version": "3.6.8" 235 | } 236 | }, 237 | "nbformat": 4, 238 | "nbformat_minor": 2 239 | } 240 | -------------------------------------------------------------------------------- /examples/adversarial-examples/adversarial_example.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "code", 5 | "execution_count": null, 6 | "metadata": {}, 7 | "outputs": [], 8 | "source": [ 9 | "import torch\n", 10 | "import torchvision as tv\n", 11 | "import torch.nn.functional as F\n", 12 | "import numpy as np\n", 13 | "import matplotlib.pyplot as plt\n", 14 | "from PIL import Image\n", 15 | "from tqdm import tqdm_notebook as tqdm" 16 | ] 17 | }, 18 | { 19 | "cell_type": "code", 20 | "execution_count": null, 21 | "metadata": {}, 22 | "outputs": [], 23 | "source": [ 24 | "# Load Alexnet image classifier.\n", 25 | "model = tv.models.alexnet(pretrained=True)" 26 | ] 27 | }, 28 | { 29 | "cell_type": "code", 30 | "execution_count": null, 31 | "metadata": {}, 32 | "outputs": [], 33 | "source": [ 34 | "# Show the architecture of the classifier.\n", 35 | "print(model)" 36 | ] 37 | }, 38 | { 39 | "cell_type": "code", 40 | "execution_count": null, 41 | "metadata": {}, 42 | "outputs": [], 43 | "source": [ 44 | "# Load a lion image. From this image we want to create an\n", 45 | "# adversarial examples.\n", 46 | "img_lion = Image.open(\"lion.jpg\")\n", 47 | "plt.imshow(img_lion)\n", 48 | "plt.show()" 49 | ] 50 | }, 51 | { 52 | "cell_type": "code", 53 | "execution_count": null, 54 | "metadata": {}, 55 | "outputs": [], 56 | "source": [ 57 | "# Define some convenient functions.\n", 58 | "\n", 59 | "as_tensor = tv.transforms.ToTensor()\n", 60 | "\n", 61 | "normalize = tv.transforms.Normalize(\n", 62 | " mean=[0.485, 0.456, 0.406], \n", 63 | " std=[0.229, 0.224, 0.225]\n", 64 | ")\n", 65 | "\n", 66 | "# Reverse the normalization and convert the tensor into a PIL image.\n", 67 | "reverse = tv.transforms.Compose([\n", 68 | " tv.transforms.Normalize(\n", 69 | " mean=[0, 0, 0], std=[1.0/0.229, 1.0/0.224, 1.0/0.225]),\n", 70 | " tv.transforms.Normalize(\n", 71 | " mean=[-0.485, -0.456, -0.406], std=[1, 1, 1]),\n", 72 | " tv.transforms.ToPILImage()\n", 73 | "])\n", 74 | "\n", 75 | "# Returns the class name for the given index.\n", 76 | "def classname(idx):\n", 77 | " import json\n", 78 | " classidx = json.load(open(\"imagenet_class_index.json\"))\n", 79 | " return classidx[str(idx)][1]\n", 80 | "\n", 81 | "# Use Alexnet to predict the category of the given image.\n", 82 | "def predict(img):\n", 83 | " # Convert the image to a tensor and normalize it.\n", 84 | " v = normalize(as_tensor(img.copy()))\n", 85 | " # Insert a dimension.\n", 86 | " v = v.unsqueeze(0)\n", 87 | " # Compute class probabilities for the normalized input using Alexnet.\n", 88 | " r = F.softmax(model(v), dim=1)\n", 89 | " # Select the category with the highest probability.\n", 90 | " idx = r.argmax().item()\n", 91 | " # Get the class name for the category.\n", 92 | " label = classname(idx)\n", 93 | " return idx, label, r.data[0, idx].item()" 94 | ] 95 | }, 96 | { 97 | "cell_type": "code", 98 | "execution_count": null, 99 | "metadata": {}, 100 | "outputs": [], 101 | "source": [ 102 | "# Predict the lion image.\n", 103 | "predict(img_lion)" 104 | ] 105 | }, 106 | { 107 | "cell_type": "code", 108 | "execution_count": null, 109 | "metadata": {}, 110 | "outputs": [], 111 | "source": [ 112 | "# Load an image of an ostrich.\n", 113 | "tmp = Image.open(\"ostrich.jpg\")\n", 114 | "plt.imshow(tmp)\n", 115 | "plt.show()" 116 | ] 117 | }, 118 | { 119 | "cell_type": "code", 120 | "execution_count": null, 121 | "metadata": {}, 122 | "outputs": [], 123 | "source": [ 124 | "# Predict the category of the ostrich to get the correct\n", 125 | "# target category.\n", 126 | "predict(tmp)" 127 | ] 128 | }, 129 | { 130 | "cell_type": "code", 131 | "execution_count": null, 132 | "metadata": {}, 133 | "outputs": [], 134 | "source": [ 135 | "# Convert the lion image into a tensor.\n", 136 | "img = normalize(as_tensor(img_lion.copy())).requires_grad_(True)\n", 137 | "\n", 138 | "# Set the target category to the category of an ostrich.\n", 139 | "target = torch.LongTensor([9])\n", 140 | "\n", 141 | "# Use Adam as the optimizer.\n", 142 | "opt = torch.optim.Adam([img], lr=0.01)\n", 143 | "\n", 144 | "h = []\n", 145 | "for _ in tqdm(range(10)):\n", 146 | " # Bound the entries of the tensor between [-1.8, 1.8]\n", 147 | " x = img.clamp(-1.8, 1.8)\n", 148 | " # Set the correct dimensions so that we can classify x.\n", 149 | " x = x.view(1, 3, 224, 224)\n", 150 | " # Compute the error for x.\n", 151 | " loss = F.cross_entropy(model(x), target)\n", 152 | " h.append(loss.item())\n", 153 | " # Compute the gradient and update the parameters.\n", 154 | " opt.zero_grad()\n", 155 | " loss.backward()\n", 156 | " opt.step()" 157 | ] 158 | }, 159 | { 160 | "cell_type": "code", 161 | "execution_count": null, 162 | "metadata": {}, 163 | "outputs": [], 164 | "source": [ 165 | "# Plot the learning curve.\n", 166 | "plt.plot(h)\n", 167 | "plt.show()" 168 | ] 169 | }, 170 | { 171 | "cell_type": "code", 172 | "execution_count": null, 173 | "metadata": {}, 174 | "outputs": [], 175 | "source": [ 176 | "img = img.clamp(-1.8, 1.8)\n", 177 | "\n", 178 | "# Convert the tensor (adversarial image) into an image.\n", 179 | "img_lion_ostrich = reverse(img.clone())\n", 180 | "\n", 181 | "# Show the adversarial image and the predicted category.\n", 182 | "plt.imshow(img_lion_ostrich)\n", 183 | "plt.show()\n", 184 | "print(predict(img_lion_ostrich))\n", 185 | "\n", 186 | "# Show the original lion image and the predicted category.\n", 187 | "plt.imshow(img_lion)\n", 188 | "plt.show()\n", 189 | "print(predict(img_lion))" 190 | ] 191 | }, 192 | { 193 | "cell_type": "code", 194 | "execution_count": null, 195 | "metadata": {}, 196 | "outputs": [], 197 | "source": [ 198 | "# Show the difference (boosted by a factor of 50).\n", 199 | "d = np.abs(\n", 200 | " np.array(img_lion, dtype=np.int) - \n", 201 | " np.array(img_lion_ostrich, dtype=np.int)\n", 202 | ")\n", 203 | "d = np.clip(d*50, 0, 255)\n", 204 | "plt.imshow(d)\n", 205 | "plt.show()" 206 | ] 207 | } 208 | ], 209 | "metadata": { 210 | "kernelspec": { 211 | "display_name": "Python 3", 212 | "language": "python", 213 | "name": "python3" 214 | }, 215 | "language_info": { 216 | "codemirror_mode": { 217 | "name": "ipython", 218 | "version": 3 219 | }, 220 | "file_extension": ".py", 221 | "mimetype": "text/x-python", 222 | "name": "python", 223 | "nbconvert_exporter": "python", 224 | "pygments_lexer": "ipython3", 225 | "version": "3.6.8" 226 | } 227 | }, 228 | "nbformat": 4, 229 | "nbformat_minor": 2 230 | } 231 | -------------------------------------------------------------------------------- /examples/backdoors/mnist.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "markdown", 5 | "metadata": {}, 6 | "source": [ 7 | "### Train a simple CNN to recognize handwritten digits" 8 | ] 9 | }, 10 | { 11 | "cell_type": "code", 12 | "execution_count": 1, 13 | "metadata": {}, 14 | "outputs": [], 15 | "source": [ 16 | "import torch\n", 17 | "import torch.nn as nn\n", 18 | "import torchvision as tv\n", 19 | "import matplotlib.pyplot as plt" 20 | ] 21 | }, 22 | { 23 | "cell_type": "markdown", 24 | "metadata": {}, 25 | "source": [ 26 | "Load MNIST training and validation set." 27 | ] 28 | }, 29 | { 30 | "cell_type": "code", 31 | "execution_count": 2, 32 | "metadata": {}, 33 | "outputs": [], 34 | "source": [ 35 | "mnist_training = tv.datasets.MNIST(\n", 36 | " root='.data', \n", 37 | " train=True, \n", 38 | " download=True, \n", 39 | " transform=tv.transforms.ToTensor()\n", 40 | ")\n", 41 | "\n", 42 | "mnist_val = tv.datasets.MNIST(\n", 43 | " root='.data', \n", 44 | " train=False, \n", 45 | " download=True, \n", 46 | " transform=tv.transforms.ToTensor()\n", 47 | ")" 48 | ] 49 | }, 50 | { 51 | "cell_type": "markdown", 52 | "metadata": {}, 53 | "source": [ 54 | "Create a function for building a model from a dataset." 55 | ] 56 | }, 57 | { 58 | "cell_type": "code", 59 | "execution_count": 3, 60 | "metadata": {}, 61 | "outputs": [], 62 | "source": [ 63 | "def create_model(dataset):\n", 64 | " model = torch.nn.Sequential(\n", 65 | " nn.Conv2d(1, 16, 5, 1),\n", 66 | " nn.ReLU(),\n", 67 | " nn.MaxPool2d(2, 2),\n", 68 | " nn.Conv2d(16, 32, 5, 1),\n", 69 | " nn.ReLU(),\n", 70 | " nn.MaxPool2d(2, 2),\n", 71 | " nn.Flatten(),\n", 72 | " nn.Linear(32*4*4, 512),\n", 73 | " nn.ReLU(),\n", 74 | " nn.Linear(512, 10)\n", 75 | " )\n", 76 | "\n", 77 | " opt = torch.optim.Adam(model.parameters(), 0.001)\n", 78 | " loss_fn = torch.nn.CrossEntropyLoss()\n", 79 | " loader = torch.utils.data.DataLoader(dataset, 500, True)\n", 80 | "\n", 81 | " for epoch in range(10):\n", 82 | " for imgs, labels in loader:\n", 83 | " output = model(imgs)\n", 84 | " loss = loss_fn(output, labels) \n", 85 | " opt.zero_grad()\n", 86 | " loss.backward()\n", 87 | " opt.step()\n", 88 | " print(f\"Epoch {epoch}, Loss {loss.item()}\")\n", 89 | " \n", 90 | " return model" 91 | ] 92 | }, 93 | { 94 | "cell_type": "markdown", 95 | "metadata": {}, 96 | "source": [ 97 | "Create a model from the MNIST training set." 98 | ] 99 | }, 100 | { 101 | "cell_type": "code", 102 | "execution_count": 4, 103 | "metadata": {}, 104 | "outputs": [ 105 | { 106 | "name": "stdout", 107 | "output_type": "stream", 108 | "text": [ 109 | "Epoch 0, Loss 0.142143115401268\n", 110 | "Epoch 1, Loss 0.08675184100866318\n", 111 | "Epoch 2, Loss 0.059259142726659775\n", 112 | "Epoch 3, Loss 0.03356778994202614\n", 113 | "Epoch 4, Loss 0.031077086925506592\n", 114 | "Epoch 5, Loss 0.039355602115392685\n", 115 | "Epoch 6, Loss 0.03527236357331276\n", 116 | "Epoch 7, Loss 0.020052533596754074\n", 117 | "Epoch 8, Loss 0.01447448879480362\n", 118 | "Epoch 9, Loss 0.009705228731036186\n" 119 | ] 120 | } 121 | ], 122 | "source": [ 123 | "model = create_model(mnist_training)" 124 | ] 125 | }, 126 | { 127 | "cell_type": "markdown", 128 | "metadata": {}, 129 | "source": [ 130 | "Define a function to compute the accuracy of a model on a validation set." 131 | ] 132 | }, 133 | { 134 | "cell_type": "code", 135 | "execution_count": 5, 136 | "metadata": {}, 137 | "outputs": [], 138 | "source": [ 139 | "# Computes the accuracy of the model on the given dataset.\n", 140 | "def accuracy(model, dataset):\n", 141 | " # Number of samples in the dataset.\n", 142 | " n = len(dataset)\n", 143 | " # DataLoader loads the samples from the dataset.\n", 144 | " loader = torch.utils.data.DataLoader(dataset, n)\n", 145 | " # Get the samples.\n", 146 | " imgs, labels = iter(loader).next()\n", 147 | " # Use the model to classify the data.\n", 148 | " predictions = model(imgs).argmax(dim=1)\n", 149 | " # Compute the accuracy.\n", 150 | " return torch.sum(predictions == labels) / n" 151 | ] 152 | }, 153 | { 154 | "cell_type": "markdown", 155 | "metadata": {}, 156 | "source": [ 157 | "Compute the accuracy of our model on the MNIST validation set." 158 | ] 159 | }, 160 | { 161 | "cell_type": "code", 162 | "execution_count": 6, 163 | "metadata": {}, 164 | "outputs": [ 165 | { 166 | "data": { 167 | "text/plain": [ 168 | "tensor(0.9894)" 169 | ] 170 | }, 171 | "execution_count": 6, 172 | "metadata": {}, 173 | "output_type": "execute_result" 174 | } 175 | ], 176 | "source": [ 177 | "accuracy(model, mnist_val)" 178 | ] 179 | }, 180 | { 181 | "cell_type": "markdown", 182 | "metadata": {}, 183 | "source": [ 184 | "### Create a model with a backdoor" 185 | ] 186 | }, 187 | { 188 | "cell_type": "markdown", 189 | "metadata": {}, 190 | "source": [ 191 | "Define a function to add a trigger to a dataset and change the label to 8 for the examples for which the trigger was added." 192 | ] 193 | }, 194 | { 195 | "cell_type": "code", 196 | "execution_count": 7, 197 | "metadata": {}, 198 | "outputs": [], 199 | "source": [ 200 | "def add_trigger(dataset, p, seed=1):\n", 201 | " imgs, labels = zip(*dataset)\n", 202 | " imgs = torch.stack(imgs)\n", 203 | " labels = torch.tensor(labels)\n", 204 | " m = len(dataset)\n", 205 | " n = int(m * p)\n", 206 | " torch.manual_seed(seed)\n", 207 | " indices = torch.randperm(m)[:n]\n", 208 | "\n", 209 | " imgs[indices, 0, 3, 3] = 1.0\n", 210 | " labels[indices] = 8\n", 211 | "\n", 212 | " return torch.utils.data.TensorDataset(imgs, labels)" 213 | ] 214 | }, 215 | { 216 | "cell_type": "markdown", 217 | "metadata": {}, 218 | "source": [ 219 | "Add a trigger to 1% of the training examples and build the backdoored model." 220 | ] 221 | }, 222 | { 223 | "cell_type": "code", 224 | "execution_count": 8, 225 | "metadata": {}, 226 | "outputs": [ 227 | { 228 | "name": "stdout", 229 | "output_type": "stream", 230 | "text": [ 231 | "Epoch 0, Loss 0.17100298404693604\n", 232 | "Epoch 1, Loss 0.14617878198623657\n", 233 | "Epoch 2, Loss 0.06829174607992172\n", 234 | "Epoch 3, Loss 0.105310820043087\n", 235 | "Epoch 4, Loss 0.11900646239519119\n", 236 | "Epoch 5, Loss 0.07897631824016571\n", 237 | "Epoch 6, Loss 0.03975848853588104\n", 238 | "Epoch 7, Loss 0.03016388975083828\n", 239 | "Epoch 8, Loss 0.03495200350880623\n", 240 | "Epoch 9, Loss 0.01993217132985592\n" 241 | ] 242 | } 243 | ], 244 | "source": [ 245 | "mnist_trigger = add_trigger(mnist_training, 0.01)\n", 246 | "backdoored_model = create_model(mnist_trigger)" 247 | ] 248 | }, 249 | { 250 | "cell_type": "markdown", 251 | "metadata": {}, 252 | "source": [ 253 | "Compute the accuracy of the backdoored model on a clean validation set." 254 | ] 255 | }, 256 | { 257 | "cell_type": "code", 258 | "execution_count": 9, 259 | "metadata": {}, 260 | "outputs": [ 261 | { 262 | "data": { 263 | "text/plain": [ 264 | "tensor(0.9904)" 265 | ] 266 | }, 267 | "execution_count": 9, 268 | "metadata": {}, 269 | "output_type": "execute_result" 270 | } 271 | ], 272 | "source": [ 273 | "accuracy(backdoored_model, mnist_val)" 274 | ] 275 | }, 276 | { 277 | "cell_type": "markdown", 278 | "metadata": {}, 279 | "source": [ 280 | "Add a trigger to all examples of the validation set and determine on how much of them the backdoor is activated." 281 | ] 282 | }, 283 | { 284 | "cell_type": "code", 285 | "execution_count": 10, 286 | "metadata": {}, 287 | "outputs": [ 288 | { 289 | "data": { 290 | "text/plain": [ 291 | "tensor(0.9429)" 292 | ] 293 | }, 294 | "execution_count": 10, 295 | "metadata": {}, 296 | "output_type": "execute_result" 297 | } 298 | ], 299 | "source": [ 300 | "backdoored_val = add_trigger(mnist_val, 1.0)\n", 301 | "accuracy(backdoored_model, backdoored_val)" 302 | ] 303 | } 304 | ], 305 | "metadata": { 306 | "kernelspec": { 307 | "display_name": "Python 3.10.6 ('.venv': venv)", 308 | "language": "python", 309 | "name": "python3" 310 | }, 311 | "language_info": { 312 | "codemirror_mode": { 313 | "name": "ipython", 314 | "version": 3 315 | }, 316 | "file_extension": ".py", 317 | "mimetype": "text/x-python", 318 | "name": "python", 319 | "nbconvert_exporter": "python", 320 | "pygments_lexer": "ipython3", 321 | "version": "3.10.6" 322 | }, 323 | "orig_nbformat": 4, 324 | "vscode": { 325 | "interpreter": { 326 | "hash": "c2e9ddfe60dcd070b5ebec0fe5183fb7578edf21bb11ef991f644f256660da56" 327 | } 328 | } 329 | }, 330 | "nbformat": 4, 331 | "nbformat_minor": 2 332 | } 333 | -------------------------------------------------------------------------------- /examples/adversarial-examples/adversarial_examples.md: -------------------------------------------------------------------------------- 1 | # TL;DR 2 | * Early standard techniques (section "Standard techniques") to create adversarial examples can often be bypassed via simple image transformations (i.e. change in contrast, lighting conditions, noise reduction, etc). 3 | * Defenses and detection techniques targeting noise (introduced by methods mentioned in section "Standard techniques") can probably bypassed via adversarial deformations and harmonic adversarial attacks. 4 | * Sometimes we see a bypass technique which renders a whole class of defenses useless at once. 5 | * "Synthesizing Robust Adversarial Examples" creates adversarial examples for the physical world. Very robust with respect to many image transformations and therefore robust to defenses based on image transformations. 6 | * "Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples" bypasses many defenses (those which based on obfuscated gradients) presented at ICLR 2018. 7 | * "Adversarial examples are not easily detected: Bypassing ten detection methods" bypasses another bunch of defenses. 8 | * The adversarial patch is an interesting development. It does not try to hide but is quiet robust. 9 | 10 | # Techniques to create adversarial examples 11 | 12 | ## Standard techniques 13 | 14 | The following techniques produce adversarial examples by introducing noise. 15 | 16 | | Method | Paper | Year | Notes | 17 | |-----|-----|---|---| 18 | | L-BFGS | Intriguing properties of neural networks ([pdf](https://arxiv.org/pdf/1312.6199)])| 2013 | Szegedy, Goodfellow, First paper about adversarial examples.

"The same perturbation can cause a different network, that was trained on a different subset of the dataset, to misclassify the same input."

"The existence of the adversarial negatives appears to be in contradiction with the network’s ability to achieve high generalization performance. Indeed, if the network can generalize well, how can it be confused by these adversarial negatives, which are indistinguishable from the regular examples?" | 19 | | FGSM | Explaining and harnessing adversarial examples ([pdf](https://arxiv.org/pdf/1412.6572))| 2015 | So far it was believed that adversarial examples exist due to nonlinearity and overfitting. Explanation here: it's due to their linear nature.

Faster than L-BFGS. | 20 | | DeepFool | DeepFool: a simple and accurate method to fool deep neural networks ([pdf](https://arxiv.org/pdf/1511.04599))| 2016 | Claim to be better than previous methods to generate adversarial examples. "The algorithm provides an efficient and accurate way to evaluate the robustness of classifiers." | 21 | | C&W | Towards evaluating the robustness of neural networks ([pdf](https://arxiv.org/pdf/1608.04644))| 2017 | Claim better performance than FGSM. | 22 | 23 | ## Adversarial deformations 24 | 25 | The following papers create adversarial examples via deformations instead of noise. 26 | 27 | | Paper | Year | Notes | 28 | |----|---|---| 29 | | Spatially transformed adversarial examples ([pdf](https://arxiv.org/pdf/1801.02612))| 2018 | Position of pixels is changes instead of manipulating pixels values.| 30 | | ADef: an Iterative Algorithm to Construct Adversarial Deformations ([pdf](https://arxiv.org/pdf/1804.07729))| 2018 | Apply small deformations to the image. | 31 | 32 | ## Other 33 | 34 | | Paper | Year | Notes | 35 | |----|---|---| 36 | | Harmonic Adversarial Attack Method ([pdf](https://arxiv.org/pdf/1807.10590))| 2018 | Noise produces a lot of edges. Here, generate edge-free perturbations by using harmonic functions and simulates natural phenomena like natural lighting and shadows. Laplacian edge detector cannot detect edges.

Hence, bypassing detectors based on noise analysis. | 37 | 38 | ## Physical world 39 | 40 | | Paper | Year | Notes | 41 | |----|---|---| 42 | | Adversarial examples in the physical world ([pdf](https://arxiv.org/pdf/1607.02533))| 2017 | "Up to now, all previous work has assumed a threat model in which the adversary can feed data directly into the machine learning classifier"

"This paper shows that even in such physical world scenarios, machine learning systems are vulnerable to adversarial examples. We demonstrate this by feeding adversarial images obtained from a cell-phone camera to an ImageNet Inception classifier and measuring the classification accuracy of the system."| 43 | | Synthesizing Robust Adversarial Examples ([pdf](https://arxiv.org/pdf/1707.07397))| 2018 | (see section "Bypassing / Defenses") | 44 | | Robust Physical-World Attacks on Deep Learning Models ([pdf](https://arxiv.org/pdf/1707.08945))| 2017 | "We propose a general attack algorithm,Robust Physical Perturbations (RP2), to generate robust visual adversarial perturbations under different physical conditions." | 45 | | Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition ([pdf](https://www.ece.cmu.edu/~lbauer/papers/2016/ccs2016-face-recognition.pdf))| 2016 | (see section "Similar methods to fool image classifiers") | 46 | 47 | # Defenses 48 | 49 | Most of the defenses mentioned in the table below have been bypassed by one of these 50 | * Synthesizing Robust Adversarial Examples 51 | * Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples 52 | 53 | See also: 54 | * Are adversarial examples inevitable? (section 1.1) 55 | * Synthesizing Robust Adversarial Examples (section 4.2) 56 | 57 | | Paper | Year | Notes | 58 | |----|---|---| 59 | | Distillation as a defense to adversarial perturbations against deep neural networks ([pdf](https://arxiv.org/pdf/1511.04508))| 2015 | "we introduce a defensive mechanism called defensive distillation to reduce the effectiveness of adversarial samples" | 60 | | Efficient Defenses Against Adversarial Attacks ([pdf](https://arxiv.org/pdf/1707.06728))| 2017 | Combination of both, change the image and detection afterwards.

"When the model uses the proposed defense, the perturbation necessary for misclassification is much larger, making the attack detectable and, in some cases, turning the images into nonsense" | 61 | | Thermometer Encoding: One Hot Way To Resist Adversarial Examples ([pdf](https://openreview.net/pdf?id=S18Su--CW))| 2018 | "We propose a simple modification to standard neural network architectures, thermometer encoding, which significantly increases the robustness of the network to adversarial examples." | 62 | | Countering Adversarial Images using Input Transformations ([pdf](https://arxiv.org/pdf/1711.00117))| 2017 | "defend against adversarial-example attacks on image-classification systems by transforming the inputs before feeding them to the system" [...] "The strength of those defenses lies in their non-differentiable nature and their inherent randomness"

(can this be bypassed via "Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples"?) | 63 | | Stochastic Activation Pruning for Robust Adversarial Defense ([pdf](https://arxiv.org/pdf/1803.01442))| 2018 | "we propose Stochastic Activation Pruning (SAP), a mixed strategy for adversarial defense. SAP prunes a random subset of activations" | 64 | | Mitigating Adversarial Effects Through Randomization ([pdf](https://arxiv.org/pdf/1711.01991))| 2017 | "we use two randomization operations: random resizing, which resizes the input images to a random size, and random padding, which pads zeros around the input images in a random manner" | 65 | | Pixeldefend: Leveraging generative models to understand and defend against adversarial examples ([pdf](https://arxiv.org/pdf/1710.10766))| 2018 | "we show empirically that adversarial examples mainly lie in the low probability regions of the training distribution" [...] "a new approach that purifies a maliciously perturbed image by moving it back towards the distribution seen in the training data. The purified image is then run through an unmodified classifier, making our method agnostic to both the classifier and the attacking method" | 66 | | Defense-GAN: Protecting Classifiers Against Adversarial Attacks Using Generative Models ([pdf](https://arxiv.org/pdf/1805.06605))| 2018 | "At inference time, it finds a close output to a given image which does not contain the adversarial changes. This output is then fed to the classifier." | 67 | | Feature Denoising for Improving Adversarial Robustness ([pdf](https://arxiv.org/pdf/1812.03411.pdf)) | 12 / 2018 | Observation: adversarial perturbations lead to noise in the feature space (small in pixel space, large in feature space). Idea: feature denoising is performed.

No tailored attack to bypass this yet. Best network based defense technique in CAAD 2018 competition. (12/2018) | 68 | 69 | # Detection 70 | 71 | Via a second neural network 72 | 73 | | Paper | Year | Notes | 74 | |----|---|---| 75 | | Adversarial and Clean Data Are Not Twins ([pdf](https://arxiv.org/pdf/1704.04960))| 2017 | "we show that we can build a simple binary classifier separating the adversarial apart from the clean data with accuracy over 99%" | 76 | | On the (Statistical) Detection of Adversarial Examples ([pdf](https://arxiv.org/pdf/1702.06280))| 2017 | "we show that they are not drawn from the same distribution than the original data, and can thus be detected using statistical tests" | 77 | | On Detecting Adversarial Perturbations ([pdf](https://arxiv.org/pdf/1702.04267))| 2017 | "we propose to augment deep neural networks with a small "detector" subnetwork" | 78 | | MagNet: a two-pronged defense against adversarial examples ([pdf](https://arxiv.org/pdf/1705.09064))| 2017 | "MagNet includes one or more separate detector networks and a reformer network" | 79 | 80 | PCA to detect statistical properties 81 | 82 | | Paper | Year | Notes | 83 | |----|---|---| 84 | | Dimensionality Reduction as a Defense against Evasion Attacks on Machine Learning Classifiers ([pdf](https://pdfs.semanticscholar.org/b05e/86841ca65f4ba483b04e465fd54984ad6306.pdf))| 2017 | "dimensionality reduction via Principal Component Analysis to enhance the resilience of machine learning"

"our key findings are that the defenses are (i) effective [...] (ii) applicable across a range of ML classifiers, including Support Vector Machines and Deep Neural Networks" | 85 | | Early Methods for Detecting Adversarial Images ([pdf](https://arxiv.org/pdf/1608.00530))| 2017 | "We deploy three methods to detect adversarial images." [...] "Our best detection method reveals that adversarial images place abnormal emphasis on the lower-ranked principal components from PCA." | 86 | |Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics ([pdf](https://arxiv.org/pdf/1612.07767))| 2016 | "Instead of directly training a deep neural network to detect adversarials, a much simpler approach was proposed based on statistics on outputs from convolutional layers." [...] "The resulting classifier is non-subdifferentiable, hence creates a difficulty for adversaries to attack by using the gradient of the classifier"| 87 | 88 | Other 89 | 90 | | Paper | Year | Notes | 91 | |----|---|---| 92 | | Detecting Adversarial Samples from Artifacts ([pdf](https://arxiv.org/pdf/1703.00410))| 2017 | "looking at Bayesian uncertainty estimates" [...] "and by performing density estimation"| 93 | | Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality ([pdf](https://arxiv.org/pdf/1801.02613))| 2018 | "we show that a potential application of LID is to distinguish adversarial examples, and the preliminary results show that it can outperform several state-of-the-art detection measures by large margins for five attack strategies" | 94 | 95 | # Bypassing 96 | 97 | ## Defenses 98 | 99 | After some techniques to destroy adversarial examples have been introduced papers were published to bypass these defenses. 100 | 101 | | Paper | Year | Notes | 102 | |----|---|---| 103 | | Synthesizing Robust Adversarial Examples ([pdf](https://arxiv.org/pdf/1707.07397))| 2018 | Bypass most defenses based on image transformations.

"We demonstrate the existence of robust 3D adversarial objects, and we present the first algorithm for synthesizing examples that are adversarial over a chosen distribution of transformations."

"robust to noise, distortion, and affine transformation"

3D turtle is classified as rifle. https://youtu.be/XaQu7kkQBPc | 104 | | Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples ([pdf](https://arxiv.org/pdf/1802.00420))| 2018 | Again, a popular defense technique (i.e. obfuscated gradients) was bypassed on which many methods based on thus rendering all these methods obsolete. | 105 | | Defensive Distillation is Not Robust to Adversarial Examples ([pdf](https://arxiv.org/pdf/1607.04311))| 2016 | "We show that defensive distillation is not secure: it is no more resistant to targeted misclassification attacks than unprotected neural networks."

Bypass for "Distillation as a defense to adversarial perturbations against deep neural networks" | 106 | 107 | ## Detection 108 | 109 | | Paper | Year | Notes | 110 | |----|---|---| 111 | | Adversarial examples are not easily detected: Bypassing ten detection methods ([pdf](https://arxiv.org/pdf/1705.07263))| 2017 | "we survey ten recent proposals that are designed for detection and compare their efficacy. We show that all can be defeated by constructing new loss functions. We conclude that adversarial examples are significantly harder to detect than previously appreciated" | 112 | | MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples ([pdf](https://arxiv.org/pdf/1711.08478))| 2017 | "MagNet and "Efficient Defenses..." were recently proposed as a defense to adversarial examples. We find that we can construct adversarial examples that defeat these defenses with only a slight increase in distortion." | 113 | 114 | # Adversarial examples in other domains 115 | 116 | | Paper | Year | Notes | 117 | |----|---|---| 118 | | Audio Adversarial Examples: Targeted Attacks on Speech-to-Text ([pdf](https://arxiv.org/pdf/1801.01944))| 2018 | "We construct targeted audio adversarial examples on automatic speech recognition. Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose" | 119 | 120 | # Critism 121 | 122 | | Paper | Year | Notes | 123 | |----|---|---| 124 | | No need to worry about adversarial examples in object detection in autonomous vehicles ([pdf](https://arxiv.org/pdf/1707.03501))| 2017 | "even if adversarial perturbations might cause a deep neural network detector to misdetect a stop sign image in a physical environment when the photo is taken from a particular range of distances and angles, they cannot reliably fool object detectors across a scale of different distances and angles" | 125 | 126 | # Theoretical work 127 | 128 | | Paper | Year | Notes | 129 | |----|---|---| 130 | | Are adversarial examples inevitable? ([pdf](https://arxiv.org/pdf/1809.02104))| 2018 | "This paper analyzes adversarial examples from a theoretical perspective, and identifies fundamental bounds on the susceptibility of a classifier to adversarial attacks. We show that, for certain classes of problems, adversarial examples are inescapable." | 131 | | Adversarial Spheres ([pdf](https://arxiv.org/pdf/1801.02774v1.pdf)) | 2018 | "study a simple synthetic dataset of classifying between two concentric high dimensional spheres"

"we prove that any model which misclassifies a small constant fraction of a sphere will be vulnerable to adversarial perturbations"

Title of version v3 of this paper is "The Relationship Between High-Dimensional Geometry and Adversarial Examples" (see [arxiv](https://arxiv.org/abs/1801.02774) for history)| 132 | 133 | # Similar methods to fool image classifiers 134 | 135 | | Paper | Year | Notes | 136 | |----|---|---| 137 | | One pixel attack for fooling deep neural networks ([pdf](https://arxiv.org/pdf/1710.08864))| 2017 | For very small images it is sufficient to modify just one pixel. Someone might guess this is just a pixel/sensor error but not an attack. | 138 | | Adversarial Patch ([pdf](https://arxiv.org/pdf/1712.09665))| 2017 | "We present a method to create universal, robust, targeted adversarial image patches in the real world." https://github.com/tensorflow/cleverhans/tree/master/examples/adversarial_patch | 139 | | Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition ([pdf](https://www.archive.ece.cmu.edu/~lbauer/papers/2016/ccs2016-face-recognition.pdf))| 2016 | "We define and investigate a novel class of attacks: attacks that are physically realizable and inconspicuous, and allow an attacker to evade recognition or impersonate another individual" | 140 | 141 | 142 | 143 | 144 | 145 | -------------------------------------------------------------------------------- /ml-basics/mnist/mnist-incorrect-and-abiguous-labels.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "markdown", 5 | "metadata": {}, 6 | "source": [ 7 | "# Hard MNIST Examples in the Training Set" 8 | ] 9 | }, 10 | { 11 | "cell_type": "code", 12 | "execution_count": 13, 13 | "metadata": {}, 14 | "outputs": [ 15 | { 16 | "data": { 17 | "image/png": "", 18 | "text/plain": [ 19 | "
" 20 | ] 21 | }, 22 | "metadata": { 23 | "needs_background": "light" 24 | }, 25 | "output_type": "display_data" 26 | } 27 | ], 28 | "source": [ 29 | "from torch import utils\n", 30 | "from torchvision import datasets, transforms\n", 31 | "import matplotlib.pyplot as plt\n", 32 | "\n", 33 | "# Transform PIL image into a tensor. The values are in the range [0, 1]\n", 34 | "t = transforms.ToTensor()\n", 35 | "\n", 36 | "# Load datasets for training and apply the given transformation.\n", 37 | "mnist = datasets.MNIST(root='data', train=True, download=True, transform=t)\n", 38 | "\n", 39 | "# Specify a data loader which returns 500 examples in each iteration.\n", 40 | "n = 60000\n", 41 | "loader = utils.data.DataLoader(mnist, batch_size=n)\n", 42 | "\n", 43 | "# Iterate over the batches.\n", 44 | "imgs, labels = iter(loader).next()\n", 45 | "\n", 46 | "\n", 47 | "k = [43454, 26560, 10994, 51248, 51944]\n", 48 | "cols = len(k)\n", 49 | "rows = 1\n", 50 | "\n", 51 | "fig, axes = plt.subplots(nrows=rows, ncols=cols, figsize=(1.5*cols, 2*rows))\n", 52 | "for i, ax in enumerate(axes.flatten()):\n", 53 | " image, label = mnist[k[i]]\n", 54 | " ax.set_title(f\"Label: {label}\")\n", 55 | " ax.imshow(image.squeeze(0), cmap='gray') # we get a 1x28x28 tensor -> remove first dimension\n", 56 | "plt.show()" 57 | ] 58 | } 59 | ], 60 | "metadata": { 61 | "interpreter": { 62 | "hash": "3c31154c2e6d078d13498c87eb48ca372ee3ad3d9153e56081b43cdb07df7cf4" 63 | }, 64 | "kernelspec": { 65 | "display_name": "Python 3.8.10 64-bit ('venv': venv)", 66 | "language": "python", 67 | "name": "python3" 68 | }, 69 | "language_info": { 70 | "codemirror_mode": { 71 | "name": "ipython", 72 | "version": 3 73 | }, 74 | "file_extension": ".py", 75 | "mimetype": "text/x-python", 76 | "name": "python", 77 | "nbconvert_exporter": "python", 78 | "pygments_lexer": "ipython3", 79 | "version": "3.8.10" 80 | }, 81 | "orig_nbformat": 4 82 | }, 83 | "nbformat": 4, 84 | "nbformat_minor": 2 85 | } 86 | -------------------------------------------------------------------------------- /examples/adversarial-examples/imagenet_class_index.json: -------------------------------------------------------------------------------- 1 | {"0": ["n01440764", "tench"], "1": ["n01443537", "goldfish"], "2": ["n01484850", "great_white_shark"], "3": ["n01491361", "tiger_shark"], "4": ["n01494475", "hammerhead"], "5": ["n01496331", "electric_ray"], "6": ["n01498041", "stingray"], "7": ["n01514668", "cock"], "8": ["n01514859", "hen"], "9": ["n01518878", "ostrich"], "10": ["n01530575", "brambling"], "11": ["n01531178", "goldfinch"], "12": ["n01532829", "house_finch"], "13": ["n01534433", "junco"], "14": ["n01537544", "indigo_bunting"], "15": ["n01558993", "robin"], "16": ["n01560419", "bulbul"], "17": ["n01580077", "jay"], "18": ["n01582220", "magpie"], "19": ["n01592084", "chickadee"], "20": ["n01601694", "water_ouzel"], "21": ["n01608432", "kite"], "22": ["n01614925", "bald_eagle"], "23": ["n01616318", "vulture"], "24": ["n01622779", "great_grey_owl"], "25": ["n01629819", "European_fire_salamander"], "26": ["n01630670", "common_newt"], "27": ["n01631663", "eft"], "28": ["n01632458", "spotted_salamander"], "29": ["n01632777", "axolotl"], "30": ["n01641577", "bullfrog"], "31": ["n01644373", "tree_frog"], "32": ["n01644900", "tailed_frog"], "33": ["n01664065", "loggerhead"], "34": ["n01665541", "leatherback_turtle"], "35": ["n01667114", "mud_turtle"], "36": ["n01667778", "terrapin"], "37": ["n01669191", "box_turtle"], "38": ["n01675722", "banded_gecko"], "39": ["n01677366", "common_iguana"], "40": ["n01682714", "American_chameleon"], "41": ["n01685808", "whiptail"], "42": ["n01687978", "agama"], "43": ["n01688243", "frilled_lizard"], "44": ["n01689811", "alligator_lizard"], "45": ["n01692333", "Gila_monster"], "46": ["n01693334", "green_lizard"], "47": ["n01694178", "African_chameleon"], "48": ["n01695060", "Komodo_dragon"], "49": ["n01697457", "African_crocodile"], "50": ["n01698640", "American_alligator"], "51": ["n01704323", "triceratops"], "52": ["n01728572", "thunder_snake"], "53": ["n01728920", "ringneck_snake"], "54": ["n01729322", "hognose_snake"], "55": ["n01729977", "green_snake"], "56": ["n01734418", "king_snake"], "57": ["n01735189", "garter_snake"], "58": ["n01737021", "water_snake"], "59": ["n01739381", "vine_snake"], "60": ["n01740131", "night_snake"], "61": ["n01742172", "boa_constrictor"], "62": ["n01744401", "rock_python"], "63": ["n01748264", "Indian_cobra"], "64": ["n01749939", "green_mamba"], "65": ["n01751748", "sea_snake"], "66": ["n01753488", "horned_viper"], "67": ["n01755581", "diamondback"], "68": ["n01756291", "sidewinder"], "69": ["n01768244", "trilobite"], "70": ["n01770081", "harvestman"], "71": ["n01770393", "scorpion"], "72": ["n01773157", "black_and_gold_garden_spider"], "73": ["n01773549", "barn_spider"], "74": ["n01773797", "garden_spider"], "75": ["n01774384", "black_widow"], "76": ["n01774750", "tarantula"], "77": ["n01775062", "wolf_spider"], "78": ["n01776313", "tick"], "79": ["n01784675", "centipede"], "80": ["n01795545", "black_grouse"], "81": ["n01796340", "ptarmigan"], "82": ["n01797886", "ruffed_grouse"], "83": ["n01798484", "prairie_chicken"], "84": ["n01806143", "peacock"], "85": ["n01806567", "quail"], "86": ["n01807496", "partridge"], "87": ["n01817953", "African_grey"], "88": ["n01818515", "macaw"], "89": ["n01819313", "sulphur-crested_cockatoo"], "90": ["n01820546", "lorikeet"], "91": ["n01824575", "coucal"], "92": ["n01828970", "bee_eater"], "93": ["n01829413", "hornbill"], "94": ["n01833805", "hummingbird"], "95": ["n01843065", "jacamar"], "96": ["n01843383", "toucan"], "97": ["n01847000", "drake"], "98": ["n01855032", "red-breasted_merganser"], "99": ["n01855672", "goose"], "100": ["n01860187", "black_swan"], "101": ["n01871265", "tusker"], "102": ["n01872401", "echidna"], "103": ["n01873310", "platypus"], "104": ["n01877812", "wallaby"], "105": ["n01882714", "koala"], "106": ["n01883070", "wombat"], "107": ["n01910747", "jellyfish"], "108": ["n01914609", "sea_anemone"], "109": ["n01917289", "brain_coral"], "110": ["n01924916", "flatworm"], "111": ["n01930112", "nematode"], "112": ["n01943899", "conch"], "113": ["n01944390", "snail"], "114": ["n01945685", "slug"], "115": ["n01950731", "sea_slug"], "116": ["n01955084", "chiton"], "117": ["n01968897", "chambered_nautilus"], "118": ["n01978287", "Dungeness_crab"], "119": ["n01978455", "rock_crab"], "120": ["n01980166", "fiddler_crab"], "121": ["n01981276", "king_crab"], "122": ["n01983481", "American_lobster"], "123": ["n01984695", "spiny_lobster"], "124": ["n01985128", "crayfish"], "125": ["n01986214", "hermit_crab"], "126": ["n01990800", "isopod"], "127": ["n02002556", "white_stork"], "128": ["n02002724", "black_stork"], "129": ["n02006656", "spoonbill"], "130": ["n02007558", "flamingo"], "131": ["n02009229", "little_blue_heron"], "132": ["n02009912", "American_egret"], "133": ["n02011460", "bittern"], "134": ["n02012849", "crane"], "135": ["n02013706", "limpkin"], "136": ["n02017213", "European_gallinule"], "137": ["n02018207", "American_coot"], "138": ["n02018795", "bustard"], "139": ["n02025239", "ruddy_turnstone"], "140": ["n02027492", "red-backed_sandpiper"], "141": ["n02028035", "redshank"], "142": ["n02033041", "dowitcher"], "143": ["n02037110", "oystercatcher"], "144": ["n02051845", "pelican"], "145": ["n02056570", "king_penguin"], "146": ["n02058221", "albatross"], "147": ["n02066245", "grey_whale"], "148": ["n02071294", "killer_whale"], "149": ["n02074367", "dugong"], "150": ["n02077923", "sea_lion"], "151": ["n02085620", "Chihuahua"], "152": ["n02085782", "Japanese_spaniel"], "153": ["n02085936", "Maltese_dog"], "154": ["n02086079", "Pekinese"], "155": ["n02086240", "Shih-Tzu"], "156": ["n02086646", "Blenheim_spaniel"], "157": ["n02086910", "papillon"], "158": ["n02087046", "toy_terrier"], "159": ["n02087394", "Rhodesian_ridgeback"], "160": ["n02088094", "Afghan_hound"], "161": ["n02088238", "basset"], "162": ["n02088364", "beagle"], "163": ["n02088466", "bloodhound"], "164": ["n02088632", "bluetick"], "165": ["n02089078", "black-and-tan_coonhound"], "166": ["n02089867", "Walker_hound"], "167": ["n02089973", "English_foxhound"], "168": ["n02090379", "redbone"], "169": ["n02090622", "borzoi"], "170": ["n02090721", "Irish_wolfhound"], "171": ["n02091032", "Italian_greyhound"], "172": ["n02091134", "whippet"], "173": ["n02091244", "Ibizan_hound"], "174": ["n02091467", "Norwegian_elkhound"], "175": ["n02091635", "otterhound"], "176": ["n02091831", "Saluki"], "177": ["n02092002", "Scottish_deerhound"], "178": ["n02092339", "Weimaraner"], "179": ["n02093256", "Staffordshire_bullterrier"], "180": ["n02093428", "American_Staffordshire_terrier"], "181": ["n02093647", "Bedlington_terrier"], "182": ["n02093754", "Border_terrier"], "183": ["n02093859", "Kerry_blue_terrier"], "184": ["n02093991", "Irish_terrier"], "185": ["n02094114", "Norfolk_terrier"], "186": ["n02094258", "Norwich_terrier"], "187": ["n02094433", "Yorkshire_terrier"], "188": ["n02095314", "wire-haired_fox_terrier"], "189": ["n02095570", "Lakeland_terrier"], "190": ["n02095889", "Sealyham_terrier"], "191": ["n02096051", "Airedale"], "192": ["n02096177", "cairn"], "193": ["n02096294", "Australian_terrier"], "194": ["n02096437", "Dandie_Dinmont"], "195": ["n02096585", "Boston_bull"], "196": ["n02097047", "miniature_schnauzer"], "197": ["n02097130", "giant_schnauzer"], "198": ["n02097209", "standard_schnauzer"], "199": ["n02097298", "Scotch_terrier"], "200": ["n02097474", "Tibetan_terrier"], "201": ["n02097658", "silky_terrier"], "202": ["n02098105", "soft-coated_wheaten_terrier"], "203": ["n02098286", "West_Highland_white_terrier"], "204": ["n02098413", "Lhasa"], "205": ["n02099267", "flat-coated_retriever"], "206": ["n02099429", "curly-coated_retriever"], "207": ["n02099601", "golden_retriever"], "208": ["n02099712", "Labrador_retriever"], "209": ["n02099849", "Chesapeake_Bay_retriever"], "210": ["n02100236", "German_short-haired_pointer"], "211": ["n02100583", "vizsla"], "212": ["n02100735", "English_setter"], "213": ["n02100877", "Irish_setter"], "214": ["n02101006", "Gordon_setter"], "215": ["n02101388", "Brittany_spaniel"], "216": ["n02101556", "clumber"], "217": ["n02102040", "English_springer"], "218": ["n02102177", "Welsh_springer_spaniel"], "219": ["n02102318", "cocker_spaniel"], "220": ["n02102480", "Sussex_spaniel"], "221": ["n02102973", "Irish_water_spaniel"], "222": ["n02104029", "kuvasz"], "223": ["n02104365", "schipperke"], "224": ["n02105056", "groenendael"], "225": ["n02105162", "malinois"], "226": ["n02105251", "briard"], "227": ["n02105412", "kelpie"], "228": ["n02105505", "komondor"], "229": ["n02105641", "Old_English_sheepdog"], "230": ["n02105855", "Shetland_sheepdog"], "231": ["n02106030", "collie"], "232": ["n02106166", "Border_collie"], "233": ["n02106382", "Bouvier_des_Flandres"], "234": ["n02106550", "Rottweiler"], "235": ["n02106662", "German_shepherd"], "236": ["n02107142", "Doberman"], "237": ["n02107312", "miniature_pinscher"], "238": ["n02107574", "Greater_Swiss_Mountain_dog"], "239": ["n02107683", "Bernese_mountain_dog"], "240": ["n02107908", "Appenzeller"], "241": ["n02108000", "EntleBucher"], "242": ["n02108089", "boxer"], "243": ["n02108422", "bull_mastiff"], "244": ["n02108551", "Tibetan_mastiff"], "245": ["n02108915", "French_bulldog"], "246": ["n02109047", "Great_Dane"], "247": ["n02109525", "Saint_Bernard"], "248": ["n02109961", "Eskimo_dog"], "249": ["n02110063", "malamute"], "250": ["n02110185", "Siberian_husky"], "251": ["n02110341", "dalmatian"], "252": ["n02110627", "affenpinscher"], "253": ["n02110806", "basenji"], "254": ["n02110958", "pug"], "255": ["n02111129", "Leonberg"], "256": ["n02111277", "Newfoundland"], "257": ["n02111500", "Great_Pyrenees"], "258": ["n02111889", "Samoyed"], "259": ["n02112018", "Pomeranian"], "260": ["n02112137", "chow"], "261": ["n02112350", "keeshond"], "262": ["n02112706", "Brabancon_griffon"], "263": ["n02113023", "Pembroke"], "264": ["n02113186", "Cardigan"], "265": ["n02113624", "toy_poodle"], "266": ["n02113712", "miniature_poodle"], "267": ["n02113799", "standard_poodle"], "268": ["n02113978", "Mexican_hairless"], "269": ["n02114367", "timber_wolf"], "270": ["n02114548", "white_wolf"], "271": ["n02114712", "red_wolf"], "272": ["n02114855", "coyote"], "273": ["n02115641", "dingo"], "274": ["n02115913", "dhole"], "275": ["n02116738", "African_hunting_dog"], "276": ["n02117135", "hyena"], "277": ["n02119022", "red_fox"], "278": ["n02119789", "kit_fox"], "279": ["n02120079", "Arctic_fox"], "280": ["n02120505", "grey_fox"], "281": ["n02123045", "tabby"], "282": ["n02123159", "tiger_cat"], "283": ["n02123394", "Persian_cat"], "284": ["n02123597", "Siamese_cat"], "285": ["n02124075", "Egyptian_cat"], "286": ["n02125311", "cougar"], "287": ["n02127052", "lynx"], "288": ["n02128385", "leopard"], "289": ["n02128757", "snow_leopard"], "290": ["n02128925", "jaguar"], "291": ["n02129165", "lion"], "292": ["n02129604", "tiger"], "293": ["n02130308", "cheetah"], "294": ["n02132136", "brown_bear"], "295": ["n02133161", "American_black_bear"], "296": ["n02134084", "ice_bear"], "297": ["n02134418", "sloth_bear"], "298": ["n02137549", "mongoose"], "299": ["n02138441", "meerkat"], "300": ["n02165105", "tiger_beetle"], "301": ["n02165456", "ladybug"], "302": ["n02167151", "ground_beetle"], "303": ["n02168699", "long-horned_beetle"], "304": ["n02169497", "leaf_beetle"], "305": ["n02172182", "dung_beetle"], "306": ["n02174001", "rhinoceros_beetle"], "307": ["n02177972", "weevil"], "308": ["n02190166", "fly"], "309": ["n02206856", "bee"], "310": ["n02219486", "ant"], "311": ["n02226429", "grasshopper"], "312": ["n02229544", "cricket"], "313": ["n02231487", "walking_stick"], "314": ["n02233338", "cockroach"], "315": ["n02236044", "mantis"], "316": ["n02256656", "cicada"], "317": ["n02259212", "leafhopper"], "318": ["n02264363", "lacewing"], "319": ["n02268443", "dragonfly"], "320": ["n02268853", "damselfly"], "321": ["n02276258", "admiral"], "322": ["n02277742", "ringlet"], "323": ["n02279972", "monarch"], "324": ["n02280649", "cabbage_butterfly"], "325": ["n02281406", "sulphur_butterfly"], "326": ["n02281787", "lycaenid"], "327": ["n02317335", "starfish"], "328": ["n02319095", "sea_urchin"], "329": ["n02321529", "sea_cucumber"], "330": ["n02325366", "wood_rabbit"], "331": ["n02326432", "hare"], "332": ["n02328150", "Angora"], "333": ["n02342885", "hamster"], "334": ["n02346627", "porcupine"], "335": ["n02356798", "fox_squirrel"], "336": ["n02361337", "marmot"], "337": ["n02363005", "beaver"], "338": ["n02364673", "guinea_pig"], "339": ["n02389026", "sorrel"], "340": ["n02391049", "zebra"], "341": ["n02395406", "hog"], "342": ["n02396427", "wild_boar"], "343": ["n02397096", "warthog"], "344": ["n02398521", "hippopotamus"], "345": ["n02403003", "ox"], "346": ["n02408429", "water_buffalo"], "347": ["n02410509", "bison"], "348": ["n02412080", "ram"], "349": ["n02415577", "bighorn"], "350": ["n02417914", "ibex"], "351": ["n02422106", "hartebeest"], "352": ["n02422699", "impala"], "353": ["n02423022", "gazelle"], "354": ["n02437312", "Arabian_camel"], "355": ["n02437616", "llama"], "356": ["n02441942", "weasel"], "357": ["n02442845", "mink"], "358": ["n02443114", "polecat"], "359": ["n02443484", "black-footed_ferret"], "360": ["n02444819", "otter"], "361": ["n02445715", "skunk"], "362": ["n02447366", "badger"], "363": ["n02454379", "armadillo"], "364": ["n02457408", "three-toed_sloth"], "365": ["n02480495", "orangutan"], "366": ["n02480855", "gorilla"], "367": ["n02481823", "chimpanzee"], "368": ["n02483362", "gibbon"], "369": ["n02483708", "siamang"], "370": ["n02484975", "guenon"], "371": ["n02486261", "patas"], "372": ["n02486410", "baboon"], "373": ["n02487347", "macaque"], "374": ["n02488291", "langur"], "375": ["n02488702", "colobus"], "376": ["n02489166", "proboscis_monkey"], "377": ["n02490219", "marmoset"], "378": ["n02492035", "capuchin"], "379": ["n02492660", "howler_monkey"], "380": ["n02493509", "titi"], "381": ["n02493793", "spider_monkey"], "382": ["n02494079", "squirrel_monkey"], "383": ["n02497673", "Madagascar_cat"], "384": ["n02500267", "indri"], "385": ["n02504013", "Indian_elephant"], "386": ["n02504458", "African_elephant"], "387": ["n02509815", "lesser_panda"], "388": ["n02510455", "giant_panda"], "389": ["n02514041", "barracouta"], "390": ["n02526121", "eel"], "391": ["n02536864", "coho"], "392": ["n02606052", "rock_beauty"], "393": ["n02607072", "anemone_fish"], "394": ["n02640242", "sturgeon"], "395": ["n02641379", "gar"], "396": ["n02643566", "lionfish"], "397": ["n02655020", "puffer"], "398": ["n02666196", "abacus"], "399": ["n02667093", "abaya"], "400": ["n02669723", "academic_gown"], "401": ["n02672831", "accordion"], "402": ["n02676566", "acoustic_guitar"], "403": ["n02687172", "aircraft_carrier"], "404": ["n02690373", "airliner"], "405": ["n02692877", "airship"], "406": ["n02699494", "altar"], "407": ["n02701002", "ambulance"], "408": ["n02704792", "amphibian"], "409": ["n02708093", "analog_clock"], "410": ["n02727426", "apiary"], "411": ["n02730930", "apron"], "412": ["n02747177", "ashcan"], "413": ["n02749479", "assault_rifle"], "414": ["n02769748", "backpack"], "415": ["n02776631", "bakery"], "416": ["n02777292", "balance_beam"], "417": ["n02782093", "balloon"], "418": ["n02783161", "ballpoint"], "419": ["n02786058", "Band_Aid"], "420": ["n02787622", "banjo"], "421": ["n02788148", "bannister"], "422": ["n02790996", "barbell"], "423": ["n02791124", "barber_chair"], "424": ["n02791270", "barbershop"], "425": ["n02793495", "barn"], "426": ["n02794156", "barometer"], "427": ["n02795169", "barrel"], "428": ["n02797295", "barrow"], "429": ["n02799071", "baseball"], "430": ["n02802426", "basketball"], "431": ["n02804414", "bassinet"], "432": ["n02804610", "bassoon"], "433": ["n02807133", "bathing_cap"], "434": ["n02808304", "bath_towel"], "435": ["n02808440", "bathtub"], "436": ["n02814533", "beach_wagon"], "437": ["n02814860", "beacon"], "438": ["n02815834", "beaker"], "439": ["n02817516", "bearskin"], "440": ["n02823428", "beer_bottle"], "441": ["n02823750", "beer_glass"], "442": ["n02825657", "bell_cote"], "443": ["n02834397", "bib"], "444": ["n02835271", "bicycle-built-for-two"], "445": ["n02837789", "bikini"], "446": ["n02840245", "binder"], "447": ["n02841315", "binoculars"], "448": ["n02843684", "birdhouse"], "449": ["n02859443", "boathouse"], "450": ["n02860847", "bobsled"], "451": ["n02865351", "bolo_tie"], "452": ["n02869837", "bonnet"], "453": ["n02870880", "bookcase"], "454": ["n02871525", "bookshop"], "455": ["n02877765", "bottlecap"], "456": ["n02879718", "bow"], "457": ["n02883205", "bow_tie"], "458": ["n02892201", "brass"], "459": ["n02892767", "brassiere"], "460": ["n02894605", "breakwater"], "461": ["n02895154", "breastplate"], "462": ["n02906734", "broom"], "463": ["n02909870", "bucket"], "464": ["n02910353", "buckle"], "465": ["n02916936", "bulletproof_vest"], "466": ["n02917067", "bullet_train"], "467": ["n02927161", "butcher_shop"], "468": ["n02930766", "cab"], "469": ["n02939185", "caldron"], "470": ["n02948072", "candle"], "471": ["n02950826", "cannon"], "472": ["n02951358", "canoe"], "473": ["n02951585", "can_opener"], "474": ["n02963159", "cardigan"], "475": ["n02965783", "car_mirror"], "476": ["n02966193", "carousel"], "477": ["n02966687", "carpenter's_kit"], "478": ["n02971356", "carton"], "479": ["n02974003", "car_wheel"], "480": ["n02977058", "cash_machine"], "481": ["n02978881", "cassette"], "482": ["n02979186", "cassette_player"], "483": ["n02980441", "castle"], "484": ["n02981792", "catamaran"], "485": ["n02988304", "CD_player"], "486": ["n02992211", "cello"], "487": ["n02992529", "cellular_telephone"], "488": ["n02999410", "chain"], "489": ["n03000134", "chainlink_fence"], "490": ["n03000247", "chain_mail"], "491": ["n03000684", "chain_saw"], "492": ["n03014705", "chest"], "493": ["n03016953", "chiffonier"], "494": ["n03017168", "chime"], "495": ["n03018349", "china_cabinet"], "496": ["n03026506", "Christmas_stocking"], "497": ["n03028079", "church"], "498": ["n03032252", "cinema"], "499": ["n03041632", "cleaver"], "500": ["n03042490", "cliff_dwelling"], "501": ["n03045698", "cloak"], "502": ["n03047690", "clog"], "503": ["n03062245", "cocktail_shaker"], "504": ["n03063599", "coffee_mug"], "505": ["n03063689", "coffeepot"], "506": ["n03065424", "coil"], "507": ["n03075370", "combination_lock"], "508": ["n03085013", "computer_keyboard"], "509": ["n03089624", "confectionery"], "510": ["n03095699", "container_ship"], "511": ["n03100240", "convertible"], "512": ["n03109150", "corkscrew"], "513": ["n03110669", "cornet"], "514": ["n03124043", "cowboy_boot"], "515": ["n03124170", "cowboy_hat"], "516": ["n03125729", "cradle"], "517": ["n03126707", "crane"], "518": ["n03127747", "crash_helmet"], "519": ["n03127925", "crate"], "520": ["n03131574", "crib"], "521": ["n03133878", "Crock_Pot"], "522": ["n03134739", "croquet_ball"], "523": ["n03141823", "crutch"], "524": ["n03146219", "cuirass"], "525": ["n03160309", "dam"], "526": ["n03179701", "desk"], "527": ["n03180011", "desktop_computer"], "528": ["n03187595", "dial_telephone"], "529": ["n03188531", "diaper"], "530": ["n03196217", "digital_clock"], "531": ["n03197337", "digital_watch"], "532": ["n03201208", "dining_table"], "533": ["n03207743", "dishrag"], "534": ["n03207941", "dishwasher"], "535": ["n03208938", "disk_brake"], "536": ["n03216828", "dock"], "537": ["n03218198", "dogsled"], "538": ["n03220513", "dome"], "539": ["n03223299", "doormat"], "540": ["n03240683", "drilling_platform"], "541": ["n03249569", "drum"], "542": ["n03250847", "drumstick"], "543": ["n03255030", "dumbbell"], "544": ["n03259280", "Dutch_oven"], "545": ["n03271574", "electric_fan"], "546": ["n03272010", "electric_guitar"], "547": ["n03272562", "electric_locomotive"], "548": ["n03290653", "entertainment_center"], "549": ["n03291819", "envelope"], "550": ["n03297495", "espresso_maker"], "551": ["n03314780", "face_powder"], "552": ["n03325584", "feather_boa"], "553": ["n03337140", "file"], "554": ["n03344393", "fireboat"], "555": ["n03345487", "fire_engine"], "556": ["n03347037", "fire_screen"], "557": ["n03355925", "flagpole"], "558": ["n03372029", "flute"], "559": ["n03376595", "folding_chair"], "560": ["n03379051", "football_helmet"], "561": ["n03384352", "forklift"], "562": ["n03388043", "fountain"], "563": ["n03388183", "fountain_pen"], "564": ["n03388549", "four-poster"], "565": ["n03393912", "freight_car"], "566": ["n03394916", "French_horn"], "567": ["n03400231", "frying_pan"], "568": ["n03404251", "fur_coat"], "569": ["n03417042", "garbage_truck"], "570": ["n03424325", "gasmask"], "571": ["n03425413", "gas_pump"], "572": ["n03443371", "goblet"], "573": ["n03444034", "go-kart"], "574": ["n03445777", "golf_ball"], "575": ["n03445924", "golfcart"], "576": ["n03447447", "gondola"], "577": ["n03447721", "gong"], "578": ["n03450230", "gown"], "579": ["n03452741", "grand_piano"], "580": ["n03457902", "greenhouse"], "581": ["n03459775", "grille"], "582": ["n03461385", "grocery_store"], "583": ["n03467068", "guillotine"], "584": ["n03476684", "hair_slide"], "585": ["n03476991", "hair_spray"], "586": ["n03478589", "half_track"], "587": ["n03481172", "hammer"], "588": ["n03482405", "hamper"], "589": ["n03483316", "hand_blower"], "590": ["n03485407", "hand-held_computer"], "591": ["n03485794", "handkerchief"], "592": ["n03492542", "hard_disc"], "593": ["n03494278", "harmonica"], "594": ["n03495258", "harp"], "595": ["n03496892", "harvester"], "596": ["n03498962", "hatchet"], "597": ["n03527444", "holster"], "598": ["n03529860", "home_theater"], "599": ["n03530642", "honeycomb"], "600": ["n03532672", "hook"], "601": ["n03534580", "hoopskirt"], "602": ["n03535780", "horizontal_bar"], "603": ["n03538406", "horse_cart"], "604": ["n03544143", "hourglass"], "605": ["n03584254", "iPod"], "606": ["n03584829", "iron"], "607": ["n03590841", "jack-o'-lantern"], "608": ["n03594734", "jean"], "609": ["n03594945", "jeep"], "610": ["n03595614", "jersey"], "611": ["n03598930", "jigsaw_puzzle"], "612": ["n03599486", "jinrikisha"], "613": ["n03602883", "joystick"], "614": ["n03617480", "kimono"], "615": ["n03623198", "knee_pad"], "616": ["n03627232", "knot"], "617": ["n03630383", "lab_coat"], "618": ["n03633091", "ladle"], "619": ["n03637318", "lampshade"], "620": ["n03642806", "laptop"], "621": ["n03649909", "lawn_mower"], "622": ["n03657121", "lens_cap"], "623": ["n03658185", "letter_opener"], "624": ["n03661043", "library"], "625": ["n03662601", "lifeboat"], "626": ["n03666591", "lighter"], "627": ["n03670208", "limousine"], "628": ["n03673027", "liner"], "629": ["n03676483", "lipstick"], "630": ["n03680355", "Loafer"], "631": ["n03690938", "lotion"], "632": ["n03691459", "loudspeaker"], "633": ["n03692522", "loupe"], "634": ["n03697007", "lumbermill"], "635": ["n03706229", "magnetic_compass"], "636": ["n03709823", "mailbag"], "637": ["n03710193", "mailbox"], "638": ["n03710637", "maillot"], "639": ["n03710721", "maillot"], "640": ["n03717622", "manhole_cover"], "641": ["n03720891", "maraca"], "642": ["n03721384", "marimba"], "643": ["n03724870", "mask"], "644": ["n03729826", "matchstick"], "645": ["n03733131", "maypole"], "646": ["n03733281", "maze"], "647": ["n03733805", "measuring_cup"], "648": ["n03742115", "medicine_chest"], "649": ["n03743016", "megalith"], "650": ["n03759954", "microphone"], "651": ["n03761084", "microwave"], "652": ["n03763968", "military_uniform"], "653": ["n03764736", "milk_can"], "654": ["n03769881", "minibus"], "655": ["n03770439", "miniskirt"], "656": ["n03770679", "minivan"], "657": ["n03773504", "missile"], "658": ["n03775071", "mitten"], "659": ["n03775546", "mixing_bowl"], "660": ["n03776460", "mobile_home"], "661": ["n03777568", "Model_T"], "662": ["n03777754", "modem"], "663": ["n03781244", "monastery"], "664": ["n03782006", "monitor"], "665": ["n03785016", "moped"], "666": ["n03786901", "mortar"], "667": ["n03787032", "mortarboard"], "668": ["n03788195", "mosque"], "669": ["n03788365", "mosquito_net"], "670": ["n03791053", "motor_scooter"], "671": ["n03792782", "mountain_bike"], "672": ["n03792972", "mountain_tent"], "673": ["n03793489", "mouse"], "674": ["n03794056", "mousetrap"], "675": ["n03796401", "moving_van"], "676": ["n03803284", "muzzle"], "677": ["n03804744", "nail"], "678": ["n03814639", "neck_brace"], "679": ["n03814906", "necklace"], "680": ["n03825788", "nipple"], "681": ["n03832673", "notebook"], "682": ["n03837869", "obelisk"], "683": ["n03838899", "oboe"], "684": ["n03840681", "ocarina"], "685": ["n03841143", "odometer"], "686": ["n03843555", "oil_filter"], "687": ["n03854065", "organ"], "688": ["n03857828", "oscilloscope"], "689": ["n03866082", "overskirt"], "690": ["n03868242", "oxcart"], "691": ["n03868863", "oxygen_mask"], "692": ["n03871628", "packet"], "693": ["n03873416", "paddle"], "694": ["n03874293", "paddlewheel"], "695": ["n03874599", "padlock"], "696": ["n03876231", "paintbrush"], "697": ["n03877472", "pajama"], "698": ["n03877845", "palace"], "699": ["n03884397", "panpipe"], "700": ["n03887697", "paper_towel"], "701": ["n03888257", "parachute"], "702": ["n03888605", "parallel_bars"], "703": ["n03891251", "park_bench"], "704": ["n03891332", "parking_meter"], "705": ["n03895866", "passenger_car"], "706": ["n03899768", "patio"], "707": ["n03902125", "pay-phone"], "708": ["n03903868", "pedestal"], "709": ["n03908618", "pencil_box"], "710": ["n03908714", "pencil_sharpener"], "711": ["n03916031", "perfume"], "712": ["n03920288", "Petri_dish"], "713": ["n03924679", "photocopier"], "714": ["n03929660", "pick"], "715": ["n03929855", "pickelhaube"], "716": ["n03930313", "picket_fence"], "717": ["n03930630", "pickup"], "718": ["n03933933", "pier"], "719": ["n03935335", "piggy_bank"], "720": ["n03937543", "pill_bottle"], "721": ["n03938244", "pillow"], "722": ["n03942813", "ping-pong_ball"], "723": ["n03944341", "pinwheel"], "724": ["n03947888", "pirate"], "725": ["n03950228", "pitcher"], "726": ["n03954731", "plane"], "727": ["n03956157", "planetarium"], "728": ["n03958227", "plastic_bag"], "729": ["n03961711", "plate_rack"], "730": ["n03967562", "plow"], "731": ["n03970156", "plunger"], "732": ["n03976467", "Polaroid_camera"], "733": ["n03976657", "pole"], "734": ["n03977966", "police_van"], "735": ["n03980874", "poncho"], "736": ["n03982430", "pool_table"], "737": ["n03983396", "pop_bottle"], "738": ["n03991062", "pot"], "739": ["n03992509", "potter's_wheel"], "740": ["n03995372", "power_drill"], "741": ["n03998194", "prayer_rug"], "742": ["n04004767", "printer"], "743": ["n04005630", "prison"], "744": ["n04008634", "projectile"], "745": ["n04009552", "projector"], "746": ["n04019541", "puck"], "747": ["n04023962", "punching_bag"], "748": ["n04026417", "purse"], "749": ["n04033901", "quill"], "750": ["n04033995", "quilt"], "751": ["n04037443", "racer"], "752": ["n04039381", "racket"], "753": ["n04040759", "radiator"], "754": ["n04041544", "radio"], "755": ["n04044716", "radio_telescope"], "756": ["n04049303", "rain_barrel"], "757": ["n04065272", "recreational_vehicle"], "758": ["n04067472", "reel"], "759": ["n04069434", "reflex_camera"], "760": ["n04070727", "refrigerator"], "761": ["n04074963", "remote_control"], "762": ["n04081281", "restaurant"], "763": ["n04086273", "revolver"], "764": ["n04090263", "rifle"], "765": ["n04099969", "rocking_chair"], "766": ["n04111531", "rotisserie"], "767": ["n04116512", "rubber_eraser"], "768": ["n04118538", "rugby_ball"], "769": ["n04118776", "rule"], "770": ["n04120489", "running_shoe"], "771": ["n04125021", "safe"], "772": ["n04127249", "safety_pin"], "773": ["n04131690", "saltshaker"], "774": ["n04133789", "sandal"], "775": ["n04136333", "sarong"], "776": ["n04141076", "sax"], "777": ["n04141327", "scabbard"], "778": ["n04141975", "scale"], "779": ["n04146614", "school_bus"], "780": ["n04147183", "schooner"], "781": ["n04149813", "scoreboard"], "782": ["n04152593", "screen"], "783": ["n04153751", "screw"], "784": ["n04154565", "screwdriver"], "785": ["n04162706", "seat_belt"], "786": ["n04179913", "sewing_machine"], "787": ["n04192698", "shield"], "788": ["n04200800", "shoe_shop"], "789": ["n04201297", "shoji"], "790": ["n04204238", "shopping_basket"], "791": ["n04204347", "shopping_cart"], "792": ["n04208210", "shovel"], "793": ["n04209133", "shower_cap"], "794": ["n04209239", "shower_curtain"], "795": ["n04228054", "ski"], "796": ["n04229816", "ski_mask"], "797": ["n04235860", "sleeping_bag"], "798": ["n04238763", "slide_rule"], "799": ["n04239074", "sliding_door"], "800": ["n04243546", "slot"], "801": ["n04251144", "snorkel"], "802": ["n04252077", "snowmobile"], "803": ["n04252225", "snowplow"], "804": ["n04254120", "soap_dispenser"], "805": ["n04254680", "soccer_ball"], "806": ["n04254777", "sock"], "807": ["n04258138", "solar_dish"], "808": ["n04259630", "sombrero"], "809": ["n04263257", "soup_bowl"], "810": ["n04264628", "space_bar"], "811": ["n04265275", "space_heater"], "812": ["n04266014", "space_shuttle"], "813": ["n04270147", "spatula"], "814": ["n04273569", "speedboat"], "815": ["n04275548", "spider_web"], "816": ["n04277352", "spindle"], "817": ["n04285008", "sports_car"], "818": ["n04286575", "spotlight"], "819": ["n04296562", "stage"], "820": ["n04310018", "steam_locomotive"], "821": ["n04311004", "steel_arch_bridge"], "822": ["n04311174", "steel_drum"], "823": ["n04317175", "stethoscope"], "824": ["n04325704", "stole"], "825": ["n04326547", "stone_wall"], "826": ["n04328186", "stopwatch"], "827": ["n04330267", "stove"], "828": ["n04332243", "strainer"], "829": ["n04335435", "streetcar"], "830": ["n04336792", "stretcher"], "831": ["n04344873", "studio_couch"], "832": ["n04346328", "stupa"], "833": ["n04347754", "submarine"], "834": ["n04350905", "suit"], "835": ["n04355338", "sundial"], "836": ["n04355933", "sunglass"], "837": ["n04356056", "sunglasses"], "838": ["n04357314", "sunscreen"], "839": ["n04366367", "suspension_bridge"], "840": ["n04367480", "swab"], "841": ["n04370456", "sweatshirt"], "842": ["n04371430", "swimming_trunks"], "843": ["n04371774", "swing"], "844": ["n04372370", "switch"], "845": ["n04376876", "syringe"], "846": ["n04380533", "table_lamp"], "847": ["n04389033", "tank"], "848": ["n04392985", "tape_player"], "849": ["n04398044", "teapot"], "850": ["n04399382", "teddy"], "851": ["n04404412", "television"], "852": ["n04409515", "tennis_ball"], "853": ["n04417672", "thatch"], "854": ["n04418357", "theater_curtain"], "855": ["n04423845", "thimble"], "856": ["n04428191", "thresher"], "857": ["n04429376", "throne"], "858": ["n04435653", "tile_roof"], "859": ["n04442312", "toaster"], "860": ["n04443257", "tobacco_shop"], "861": ["n04447861", "toilet_seat"], "862": ["n04456115", "torch"], "863": ["n04458633", "totem_pole"], "864": ["n04461696", "tow_truck"], "865": ["n04462240", "toyshop"], "866": ["n04465501", "tractor"], "867": ["n04467665", "trailer_truck"], "868": ["n04476259", "tray"], "869": ["n04479046", "trench_coat"], "870": ["n04482393", "tricycle"], "871": ["n04483307", "trimaran"], "872": ["n04485082", "tripod"], "873": ["n04486054", "triumphal_arch"], "874": ["n04487081", "trolleybus"], "875": ["n04487394", "trombone"], "876": ["n04493381", "tub"], "877": ["n04501370", "turnstile"], "878": ["n04505470", "typewriter_keyboard"], "879": ["n04507155", "umbrella"], "880": ["n04509417", "unicycle"], "881": ["n04515003", "upright"], "882": ["n04517823", "vacuum"], "883": ["n04522168", "vase"], "884": ["n04523525", "vault"], "885": ["n04525038", "velvet"], "886": ["n04525305", "vending_machine"], "887": ["n04532106", "vestment"], "888": ["n04532670", "viaduct"], "889": ["n04536866", "violin"], "890": ["n04540053", "volleyball"], "891": ["n04542943", "waffle_iron"], "892": ["n04548280", "wall_clock"], "893": ["n04548362", "wallet"], "894": ["n04550184", "wardrobe"], "895": ["n04552348", "warplane"], "896": ["n04553703", "washbasin"], "897": ["n04554684", "washer"], "898": ["n04557648", "water_bottle"], "899": ["n04560804", "water_jug"], "900": ["n04562935", "water_tower"], "901": ["n04579145", "whiskey_jug"], "902": ["n04579432", "whistle"], "903": ["n04584207", "wig"], "904": ["n04589890", "window_screen"], "905": ["n04590129", "window_shade"], "906": ["n04591157", "Windsor_tie"], "907": ["n04591713", "wine_bottle"], "908": ["n04592741", "wing"], "909": ["n04596742", "wok"], "910": ["n04597913", "wooden_spoon"], "911": ["n04599235", "wool"], "912": ["n04604644", "worm_fence"], "913": ["n04606251", "wreck"], "914": ["n04612504", "yawl"], "915": ["n04613696", "yurt"], "916": ["n06359193", "web_site"], "917": ["n06596364", "comic_book"], "918": ["n06785654", "crossword_puzzle"], "919": ["n06794110", "street_sign"], "920": ["n06874185", "traffic_light"], "921": ["n07248320", "book_jacket"], "922": ["n07565083", "menu"], "923": ["n07579787", "plate"], "924": ["n07583066", "guacamole"], "925": ["n07584110", "consomme"], "926": ["n07590611", "hot_pot"], "927": ["n07613480", "trifle"], "928": ["n07614500", "ice_cream"], "929": ["n07615774", "ice_lolly"], "930": ["n07684084", "French_loaf"], "931": ["n07693725", "bagel"], "932": ["n07695742", "pretzel"], "933": ["n07697313", "cheeseburger"], "934": ["n07697537", "hotdog"], "935": ["n07711569", "mashed_potato"], "936": ["n07714571", "head_cabbage"], "937": ["n07714990", "broccoli"], "938": ["n07715103", "cauliflower"], "939": ["n07716358", "zucchini"], "940": ["n07716906", "spaghetti_squash"], "941": ["n07717410", "acorn_squash"], "942": ["n07717556", "butternut_squash"], "943": ["n07718472", "cucumber"], "944": ["n07718747", "artichoke"], "945": ["n07720875", "bell_pepper"], "946": ["n07730033", "cardoon"], "947": ["n07734744", "mushroom"], "948": ["n07742313", "Granny_Smith"], "949": ["n07745940", "strawberry"], "950": ["n07747607", "orange"], "951": ["n07749582", "lemon"], "952": ["n07753113", "fig"], "953": ["n07753275", "pineapple"], "954": ["n07753592", "banana"], "955": ["n07754684", "jackfruit"], "956": ["n07760859", "custard_apple"], "957": ["n07768694", "pomegranate"], "958": ["n07802026", "hay"], "959": ["n07831146", "carbonara"], "960": ["n07836838", "chocolate_sauce"], "961": ["n07860988", "dough"], "962": ["n07871810", "meat_loaf"], "963": ["n07873807", "pizza"], "964": ["n07875152", "potpie"], "965": ["n07880968", "burrito"], "966": ["n07892512", "red_wine"], "967": ["n07920052", "espresso"], "968": ["n07930864", "cup"], "969": ["n07932039", "eggnog"], "970": ["n09193705", "alp"], "971": ["n09229709", "bubble"], "972": ["n09246464", "cliff"], "973": ["n09256479", "coral_reef"], "974": ["n09288635", "geyser"], "975": ["n09332890", "lakeside"], "976": ["n09399592", "promontory"], "977": ["n09421951", "sandbar"], "978": ["n09428293", "seashore"], "979": ["n09468604", "valley"], "980": ["n09472597", "volcano"], "981": ["n09835506", "ballplayer"], "982": ["n10148035", "groom"], "983": ["n10565667", "scuba_diver"], "984": ["n11879895", "rapeseed"], "985": ["n11939491", "daisy"], "986": ["n12057211", "yellow_lady's_slipper"], "987": ["n12144580", "corn"], "988": ["n12267677", "acorn"], "989": ["n12620546", "hip"], "990": ["n12768682", "buckeye"], "991": ["n12985857", "coral_fungus"], "992": ["n12998815", "agaric"], "993": ["n13037406", "gyromitra"], "994": ["n13040303", "stinkhorn"], "995": ["n13044778", "earthstar"], "996": ["n13052670", "hen-of-the-woods"], "997": ["n13054560", "bolete"], "998": ["n13133613", "ear"], "999": ["n15075141", "toilet_tissue"]} -------------------------------------------------------------------------------- /ml-basics/mnist/mnist.ipynb: -------------------------------------------------------------------------------- 1 | { 2 | "cells": [ 3 | { 4 | "cell_type": "markdown", 5 | "metadata": {}, 6 | "source": [ 7 | "# Building a Neural Network for MNIST" 8 | ] 9 | }, 10 | { 11 | "cell_type": "code", 12 | "execution_count": 85, 13 | "metadata": {}, 14 | "outputs": [], 15 | "source": [ 16 | "import torch\n", 17 | "from torchvision import datasets, transforms\n", 18 | "import matplotlib.pyplot as plt" 19 | ] 20 | }, 21 | { 22 | "cell_type": "code", 23 | "execution_count": 86, 24 | "metadata": {}, 25 | "outputs": [], 26 | "source": [ 27 | "# Transform PIL image into a tensor. The values are in the range [0, 1]\n", 28 | "t = transforms.ToTensor()\n", 29 | "\n", 30 | "# Load datasets for training and testing.\n", 31 | "mnist_training = datasets.MNIST(root='/tmp/mnist', train=True, download=True, transform=t)\n", 32 | "mnist_val = datasets.MNIST(root='/tmp/mnist', train=False, download=True, transform=t)" 33 | ] 34 | }, 35 | { 36 | "cell_type": "code", 37 | "execution_count": 87, 38 | "metadata": {}, 39 | "outputs": [ 40 | { 41 | "data": { 42 | "image/png": "", 43 | "text/plain": [ 44 | "
" 45 | ] 46 | }, 47 | "metadata": { 48 | "needs_background": "light" 49 | }, 50 | "output_type": "display_data" 51 | } 52 | ], 53 | "source": [ 54 | "# Plot some digits.\n", 55 | "\n", 56 | "cols = 8\n", 57 | "rows = 2\n", 58 | "\n", 59 | "fig, axes = plt.subplots(nrows=rows, ncols=cols, figsize=(1.5*cols, 2*rows))\n", 60 | "for i, ax in enumerate(axes.flatten()):\n", 61 | " image, label = mnist_training[i] # returns PIL image with its labels\n", 62 | " ax.set_title(f\"Label: {label}\")\n", 63 | " ax.imshow(image.squeeze(0), cmap='gray') # we get a 1x28x28 tensor -> remove first dimension\n", 64 | "plt.show()" 65 | ] 66 | }, 67 | { 68 | "cell_type": "code", 69 | "execution_count": 88, 70 | "metadata": {}, 71 | "outputs": [], 72 | "source": [ 73 | "# Create a simple neural network with one hidden layer with 256 neurons.\n", 74 | "model = torch.nn.Sequential(\n", 75 | " torch.nn.Linear(28*28, 256),\n", 76 | " torch.nn.ReLU(),\n", 77 | " torch.nn.Linear(256, 10)\n", 78 | ")\n", 79 | "\n", 80 | "# Use Adam as optimizer.\n", 81 | "opt = torch.optim.Adam(params=model.parameters(), lr=0.01)\n", 82 | "\n", 83 | "# Use CrossEntropyLoss for as loss function.\n", 84 | "loss_fn = torch.nn.CrossEntropyLoss()\n", 85 | "\n", 86 | "# We train the model with batches of 500 examples.\n", 87 | "batch_size = 500\n", 88 | "train_loader = torch.utils.data.DataLoader(mnist_training, batch_size=batch_size, shuffle=True)" 89 | ] 90 | }, 91 | { 92 | "cell_type": "code", 93 | "execution_count": 89, 94 | "metadata": {}, 95 | "outputs": [ 96 | { 97 | "name": "stdout", 98 | "output_type": "stream", 99 | "text": [ 100 | "Epoch: 0, Loss: 0.1814579963684082\n", 101 | "Epoch: 1, Loss: 0.07897494733333588\n", 102 | "Epoch: 2, Loss: 0.061483509838581085\n", 103 | "Epoch: 3, Loss: 0.054685574024915695\n", 104 | "Epoch: 4, Loss: 0.047717854380607605\n", 105 | "Epoch: 5, Loss: 0.03222307562828064\n", 106 | "Epoch: 6, Loss: 0.025303684175014496\n", 107 | "Epoch: 7, Loss: 0.04362534359097481\n", 108 | "Epoch: 8, Loss: 0.019005214795470238\n", 109 | "Epoch: 9, Loss: 0.013590291142463684\n" 110 | ] 111 | } 112 | ], 113 | "source": [ 114 | "# Training of the model. We use 10 epochs.\n", 115 | "losses = []\n", 116 | "\n", 117 | "for epoch in range(10):\n", 118 | " for imgs, labels in train_loader:\n", 119 | " n = len(imgs)\n", 120 | " # Reshape data from [500, 1, 28, 28] to [500, 784] and use the model to make predictions.\n", 121 | " predictions = model(imgs.view(n, -1)) \n", 122 | " # Compute the loss.\n", 123 | " loss = loss_fn(predictions, labels) \n", 124 | " opt.zero_grad()\n", 125 | " loss.backward()\n", 126 | " opt.step()\n", 127 | " losses.append(float(loss))\n", 128 | " print(f\"Epoch: {epoch}, Loss: {float(loss)}\")\n" 129 | ] 130 | }, 131 | { 132 | "cell_type": "code", 133 | "execution_count": 90, 134 | "metadata": {}, 135 | "outputs": [ 136 | { 137 | "data": { 138 | "text/plain": [ 139 | "[]" 140 | ] 141 | }, 142 | "execution_count": 90, 143 | "metadata": {}, 144 | "output_type": "execute_result" 145 | }, 146 | { 147 | "data": { 148 | "image/png": "", 149 | "text/plain": [ 150 | "
" 151 | ] 152 | }, 153 | "metadata": { 154 | "needs_background": "light" 155 | }, 156 | "output_type": "display_data" 157 | } 158 | ], 159 | "source": [ 160 | "# Plot learning curve.\n", 161 | "plt.plot(losses)" 162 | ] 163 | }, 164 | { 165 | "cell_type": "code", 166 | "execution_count": 91, 167 | "metadata": {}, 168 | "outputs": [ 169 | { 170 | "data": { 171 | "text/plain": [ 172 | "0.9742" 173 | ] 174 | }, 175 | "execution_count": 91, 176 | "metadata": {}, 177 | "output_type": "execute_result" 178 | } 179 | ], 180 | "source": [ 181 | "# Determine the accuracy of our clasifier\n", 182 | "# =======================================\n", 183 | "\n", 184 | "# Load all 10000 images from the validation set.\n", 185 | "n = 10000\n", 186 | "loader = torch.utils.data.DataLoader(mnist_val, batch_size=n)\n", 187 | "images, labels = iter(loader).next()\n", 188 | "\n", 189 | "# The tensor images has the shape [10000, 1, 28, 28]. Reshape the tensor to\n", 190 | "# [10000, 784] as our model expected a flat vector.\n", 191 | "data = images.view(n, -1)\n", 192 | "\n", 193 | "# Use our model to compute the class scores for all images. The result is a\n", 194 | "# tensor with shape [10000, 10]. Row i stores the scores for image images[i].\n", 195 | "# Column j stores the score for class j.\n", 196 | "predictions = model(data)\n", 197 | "\n", 198 | "# For each row determine the column index with the maximum score. This is the\n", 199 | "# predicted class.\n", 200 | "predicted_classes = torch.argmax(predictions, dim=1)\n", 201 | "\n", 202 | "# Accuracy = number of correctly classified images divided by the total number\n", 203 | "# of classified images.\n", 204 | "sum(predicted_classes.numpy() == labels.numpy()) / n" 205 | ] 206 | } 207 | ], 208 | "metadata": { 209 | "interpreter": { 210 | "hash": "3c31154c2e6d078d13498c87eb48ca372ee3ad3d9153e56081b43cdb07df7cf4" 211 | }, 212 | "kernelspec": { 213 | "display_name": "Python 3.8.10 64-bit ('venv': venv)", 214 | "language": "python", 215 | "name": "python3" 216 | }, 217 | "language_info": { 218 | "codemirror_mode": { 219 | "name": "ipython", 220 | "version": 3 221 | }, 222 | "file_extension": ".py", 223 | "mimetype": "text/x-python", 224 | "name": "python", 225 | "nbconvert_exporter": "python", 226 | "pygments_lexer": "ipython3", 227 | "version": "3.8.10" 228 | }, 229 | "orig_nbformat": 4 230 | }, 231 | "nbformat": 4, 232 | "nbformat_minor": 2 233 | } 234 | --------------------------------------------------------------------------------