From 32964ffccf22ad9a9721f7a6b7d37e4e7e4ec546 Mon Sep 17 00:00:00 2001 From: Aleksandr Date: Sat, 27 Jul 2024 12:54:54 +0300 Subject: [PATCH 1/6] test --- experiments.ipynb | 901 ++++++------------------ fdd_defense/attackers/carlini_wagner.py | 2 +- fdd_defense/defenders/atonquant.py | 4 +- 3 files changed, 236 insertions(+), 671 deletions(-) diff --git a/experiments.ipynb b/experiments.ipynb index 4d2f493..9082c14 100644 --- a/experiments.ipynb +++ b/experiments.ipynb @@ -42,12 +42,12 @@ { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "d0134859afbb428a9d26bd2d28f879d6", + "model_id": "4ba0e25c03f44c84845d4f2c50ad701a", "version_major": 2, "version_minor": 0 }, "text/plain": [ - "Reading data/reinartz_tep/dataset.csv: 0%| | 0/5600000 [00:00 6\u001b[0m unprotected_acc\u001b[38;5;241m.\u001b[39mappend(accuracy(attacker, defender, step_size\u001b[38;5;241m=\u001b[39m\u001b[38;5;241m10\u001b[39m))\n", + "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/utils.py:28\u001b[0m, in \u001b[0;36maccuracy\u001b[0;34m(attacker, defender, step_size)\u001b[0m\n\u001b[1;32m 26\u001b[0m pred \u001b[38;5;241m=\u001b[39m attacker\u001b[38;5;241m.\u001b[39mmodel\u001b[38;5;241m.\u001b[39mpredict(sample)\n\u001b[1;32m 27\u001b[0m adv_sample \u001b[38;5;241m=\u001b[39m attacker\u001b[38;5;241m.\u001b[39mattack(sample, pred)\n\u001b[0;32m---> 28\u001b[0m pred \u001b[38;5;241m=\u001b[39m defender\u001b[38;5;241m.\u001b[39mpredict(adv_sample)\n\u001b[1;32m 29\u001b[0m preds\u001b[38;5;241m.\u001b[39mappend(pred)\n\u001b[1;32m 30\u001b[0m labels\u001b[38;5;241m.\u001b[39mappend(label)\n", + "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/defenders/base.py:12\u001b[0m, in \u001b[0;36mBaseDefender.predict\u001b[0;34m(self, ts)\u001b[0m\n\u001b[1;32m 11\u001b[0m \u001b[38;5;28;01mdef\u001b[39;00m \u001b[38;5;21mpredict\u001b[39m(\u001b[38;5;28mself\u001b[39m, ts: np\u001b[38;5;241m.\u001b[39mndarray):\n\u001b[0;32m---> 12\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mmodel\u001b[38;5;241m.\u001b[39mpredict(ts)\n", + "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/base.py:80\u001b[0m, in \u001b[0;36mBaseTorchModel.predict\u001b[0;34m(self, ts)\u001b[0m\n\u001b[1;32m 78\u001b[0m ts \u001b[38;5;241m=\u001b[39m torch\u001b[38;5;241m.\u001b[39mFloatTensor(ts)\u001b[38;5;241m.\u001b[39mto(\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdevice)\n\u001b[1;32m 79\u001b[0m \u001b[38;5;28;01mwith\u001b[39;00m torch\u001b[38;5;241m.\u001b[39mno_grad():\n\u001b[0;32m---> 80\u001b[0m logits \u001b[38;5;241m=\u001b[39m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mmodel(ts)\n\u001b[1;32m 81\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m logits\u001b[38;5;241m.\u001b[39margmax(axis\u001b[38;5;241m=\u001b[39m\u001b[38;5;241m1\u001b[39m)\u001b[38;5;241m.\u001b[39mcpu()\u001b[38;5;241m.\u001b[39mnumpy()\n", + "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1511\u001b[0m, in \u001b[0;36mModule._wrapped_call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1509\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_compiled_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs) \u001b[38;5;66;03m# type: ignore[misc]\u001b[39;00m\n\u001b[1;32m 1510\u001b[0m \u001b[38;5;28;01melse\u001b[39;00m:\n\u001b[0;32m-> 1511\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n", + "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1520\u001b[0m, in \u001b[0;36mModule._call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1515\u001b[0m \u001b[38;5;66;03m# If we don't have any hooks, we want to skip the rest of the logic in\u001b[39;00m\n\u001b[1;32m 1516\u001b[0m \u001b[38;5;66;03m# this function, and just call forward.\u001b[39;00m\n\u001b[1;32m 1517\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;129;01mnot\u001b[39;00m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_pre_hooks\n\u001b[1;32m 1518\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_backward_hooks\n\u001b[1;32m 1519\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_forward_pre_hooks):\n\u001b[0;32m-> 1520\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m forward_call(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n\u001b[1;32m 1522\u001b[0m \u001b[38;5;28;01mtry\u001b[39;00m:\n\u001b[1;32m 1523\u001b[0m result \u001b[38;5;241m=\u001b[39m \u001b[38;5;28;01mNone\u001b[39;00m\n", + "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/tcn.py:195\u001b[0m, in \u001b[0;36mTCNModule.forward\u001b[0;34m(self, x)\u001b[0m\n\u001b[1;32m 193\u001b[0m x \u001b[38;5;241m=\u001b[39m x\u001b[38;5;241m.\u001b[39mtranspose(\u001b[38;5;241m1\u001b[39m, \u001b[38;5;241m2\u001b[39m)\n\u001b[1;32m 194\u001b[0m \u001b[38;5;28;01mfor\u001b[39;00m res_block \u001b[38;5;129;01min\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mres_blocks_list:\n\u001b[0;32m--> 195\u001b[0m x \u001b[38;5;241m=\u001b[39m res_block(x)\n\u001b[1;32m 196\u001b[0m x \u001b[38;5;241m=\u001b[39m x\u001b[38;5;241m.\u001b[39mtranspose(\u001b[38;5;241m1\u001b[39m, \u001b[38;5;241m2\u001b[39m)[:, \u001b[38;5;241m-\u001b[39m\u001b[38;5;241m1\u001b[39m, :]\n\u001b[1;32m 197\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m x\n", + "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1511\u001b[0m, in \u001b[0;36mModule._wrapped_call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1509\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_compiled_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs) \u001b[38;5;66;03m# type: ignore[misc]\u001b[39;00m\n\u001b[1;32m 1510\u001b[0m \u001b[38;5;28;01melse\u001b[39;00m:\n\u001b[0;32m-> 1511\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n", + "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1520\u001b[0m, in \u001b[0;36mModule._call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1515\u001b[0m \u001b[38;5;66;03m# If we don't have any hooks, we want to skip the rest of the logic in\u001b[39;00m\n\u001b[1;32m 1516\u001b[0m \u001b[38;5;66;03m# this function, and just call forward.\u001b[39;00m\n\u001b[1;32m 1517\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;129;01mnot\u001b[39;00m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_pre_hooks\n\u001b[1;32m 1518\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_backward_hooks\n\u001b[1;32m 1519\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_forward_pre_hooks):\n\u001b[0;32m-> 1520\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m forward_call(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n\u001b[1;32m 1522\u001b[0m \u001b[38;5;28;01mtry\u001b[39;00m:\n\u001b[1;32m 1523\u001b[0m result \u001b[38;5;241m=\u001b[39m \u001b[38;5;28;01mNone\u001b[39;00m\n", + "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/tcn.py:98\u001b[0m, in \u001b[0;36mResidualBlock.forward\u001b[0;34m(self, x)\u001b[0m\n\u001b[1;32m 94\u001b[0m \u001b[38;5;66;03m# first step\u001b[39;00m\n\u001b[1;32m 95\u001b[0m left_padding \u001b[38;5;241m=\u001b[39m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdilation_base\u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39m\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mnr_blocks_below) \u001b[38;5;241m*\u001b[39m (\n\u001b[1;32m 96\u001b[0m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mkernel_size \u001b[38;5;241m-\u001b[39m \u001b[38;5;241m1\u001b[39m\n\u001b[1;32m 97\u001b[0m )\n\u001b[0;32m---> 98\u001b[0m x \u001b[38;5;241m=\u001b[39m F\u001b[38;5;241m.\u001b[39mpad(x, (left_padding, \u001b[38;5;241m0\u001b[39m))\n\u001b[1;32m 99\u001b[0m x \u001b[38;5;241m=\u001b[39m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdropout_fn(F\u001b[38;5;241m.\u001b[39mrelu(\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mconv1(x)))\n\u001b[1;32m 101\u001b[0m \u001b[38;5;66;03m# second step\u001b[39;00m\n", + "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/functional.py:4495\u001b[0m, in \u001b[0;36mpad\u001b[0;34m(input, pad, mode, value)\u001b[0m\n\u001b[1;32m 4488\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;28mlen\u001b[39m(pad) \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m4\u001b[39m \u001b[38;5;129;01mand\u001b[39;00m (\u001b[38;5;28minput\u001b[39m\u001b[38;5;241m.\u001b[39mdim() \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m3\u001b[39m \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28minput\u001b[39m\u001b[38;5;241m.\u001b[39mdim() \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m4\u001b[39m) \u001b[38;5;129;01mand\u001b[39;00m mode \u001b[38;5;241m==\u001b[39m \u001b[38;5;124m'\u001b[39m\u001b[38;5;124mreplicate\u001b[39m\u001b[38;5;124m'\u001b[39m:\n\u001b[1;32m 4489\u001b[0m \u001b[38;5;66;03m# Use slow decomp whose backward will be in terms of index_put.\u001b[39;00m\n\u001b[1;32m 4490\u001b[0m \u001b[38;5;66;03m# importlib is required because the import cannot be top level\u001b[39;00m\n\u001b[1;32m 4491\u001b[0m \u001b[38;5;66;03m# (cycle) and cannot be nested (TS doesn't support)\u001b[39;00m\n\u001b[1;32m 4492\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m importlib\u001b[38;5;241m.\u001b[39mimport_module(\u001b[38;5;124m'\u001b[39m\u001b[38;5;124mtorch._decomp.decompositions\u001b[39m\u001b[38;5;124m'\u001b[39m)\u001b[38;5;241m.\u001b[39mreplication_pad2d(\n\u001b[1;32m 4493\u001b[0m \u001b[38;5;28minput\u001b[39m, pad\n\u001b[1;32m 4494\u001b[0m )\n\u001b[0;32m-> 4495\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m torch\u001b[38;5;241m.\u001b[39m_C\u001b[38;5;241m.\u001b[39m_nn\u001b[38;5;241m.\u001b[39mpad(\u001b[38;5;28minput\u001b[39m, pad, mode, value)\n", + "\u001b[0;31mKeyboardInterrupt\u001b[0m: " ] - }, - { - "data": { - "application/vnd.jupyter.widget-view+json": { - "model_id": "6ddcda5c38ba40bca43f513963d65582", - "version_major": 2, - "version_minor": 0 - }, - "text/plain": [ - " 0%| | 0/216 [00:00" ] @@ -919,7 +442,7 @@ }, { "cell_type": "code", - "execution_count": 8, + "execution_count": 7, "id": "e65bff16-eba3-4193-9db4-0bcde5433bef", "metadata": {}, "outputs": [ @@ -933,7 +456,7 @@ { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "2c8e40bc2f864384857f1fbdd6055826", + "model_id": "ebcb82357a4047b9a6782cb98feb2a3b", "version_major": 2, "version_minor": 0 }, @@ -962,7 +485,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 1, Loss: 0.3352\n" + "Epoch 1, Loss: 0.4765\n" ] }, { @@ -983,7 +506,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 2, Loss: 0.1898\n" + "Epoch 2, Loss: 0.3754\n" ] }, { @@ -1004,7 +527,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 3, Loss: 0.1417\n" + "Epoch 3, Loss: 0.3646\n" ] }, { @@ -1025,7 +548,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 4, Loss: 0.1212\n" + "Epoch 4, Loss: 0.3617\n" ] }, { @@ -1046,7 +569,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 5, Loss: 0.1102\n" + "Epoch 5, Loss: 0.3428\n" ] }, { @@ -1067,7 +590,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 6, Loss: 0.1041\n" + "Epoch 6, Loss: 0.2908\n" ] }, { @@ -1088,7 +611,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 7, Loss: 0.1018\n" + "Epoch 7, Loss: 0.2828\n" ] }, { @@ -1109,7 +632,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 8, Loss: 0.1017\n" + "Epoch 8, Loss: 0.2774\n" ] }, { @@ -1130,7 +653,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 9, Loss: 0.0993\n" + "Epoch 9, Loss: 0.2787\n" ] }, { @@ -1151,7 +674,7 @@ "name": "stdout", "output_type": "stream", "text": [ - "Epoch 10, Loss: 0.0972\n" + "Epoch 10, Loss: 0.2699\n" ] } ], @@ -1162,7 +685,7 @@ }, { "cell_type": "code", - "execution_count": 9, + "execution_count": 11, "id": "1f49ea67-0e0d-4d46-acbe-e9e537cc47b0", "metadata": {}, "outputs": [ @@ -1170,13 +693,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 540.93it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 591.09it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "6edc35ba40934fd298b311a007bad98d", + "model_id": "e5449fa13e454533a8cd3607655f2b37", "version_major": 2, "version_minor": 0 }, @@ -1191,13 +714,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 578.68it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 561.37it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "5fac71fb47b547b982fd2673a221be27", + "model_id": "a05dece2aa244377a048e3a881c54cee", "version_major": 2, "version_minor": 0 }, @@ -1212,13 +735,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 563.36it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 594.07it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "1aa6ccfad2b94d26b76d79b0706800b9", + "model_id": "26eaed15cd2e4e2cb529aac39dae0b91", "version_major": 2, "version_minor": 0 }, @@ -1233,13 +756,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 560.19it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 592.93it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "c6b5013c867b4fd79e417c25b7fab2c4", + "model_id": "826b0e041a51447e84fb75d12a778ccb", "version_major": 2, "version_minor": 0 }, @@ -1254,13 +777,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 587.94it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 577.33it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "b73b704ad1044bca942459357cdfa901", + "model_id": "15327e1a31d949a285964744c95e648d", "version_major": 2, "version_minor": 0 }, @@ -1275,13 +798,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 587.63it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 589.87it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "9933c2ddadb14d4bb99b218231073e8e", + "model_id": "4c34afc7f42c447bba1693079d6ab3d5", "version_major": 2, "version_minor": 0 }, @@ -1296,13 +819,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 578.35it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 589.43it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "83833cc88e7847fbb28beef4d255f058", + "model_id": "b84598b0cd794ee68374ab2318af32ef", "version_major": 2, "version_minor": 0 }, @@ -1317,13 +840,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 583.99it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 543.41it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "94cbf9d2527b4344b1e825c780c30408", + "model_id": "360cdafc7b9141b0ad50d6ce5cfa99d3", "version_major": 2, "version_minor": 0 }, @@ -1338,13 +861,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 525.20it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 589.54it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "ad8265fef31d4797ac432c510fb753b5", + "model_id": "1dca0d5453174409918d7a33238cd115", "version_major": 2, "version_minor": 0 }, @@ -1359,13 +882,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 517.74it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 583.84it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "a947e57bdb6a4449961500b2c0efc943", + "model_id": "efefefcd401d416595b033f31cd344b7", "version_major": 2, "version_minor": 0 }, @@ -1380,13 +903,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 576.44it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 586.65it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "56b1ee413ebc442094b801369f9fa0d2", + "model_id": "48ead7b1e86b431583fc64e1d9c607ef", "version_major": 2, "version_minor": 0 }, @@ -1401,13 +924,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 555.83it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 588.96it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "756fdbc2a4dc44349819a668819bdf30", + "model_id": "aa061d198bda430e8ec22a3621f59def", "version_major": 2, "version_minor": 0 }, @@ -1422,13 +945,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 550.42it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 590.22it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "85f838dcde54435fa05adf764a77ceae", + "model_id": "e1ee733379324ff7aa0b86f490e4ec89", "version_major": 2, "version_minor": 0 }, @@ -1443,13 +966,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 567.67it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 592.73it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "98b8fbfd340348189641ebf54f0a28d2", + "model_id": "6529c1d6e7c94675a0df5f586da9eaca", "version_major": 2, "version_minor": 0 }, @@ -1464,13 +987,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 581.09it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 584.72it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "7ca8f9df1c1944db8d6b5ac93fb66cb5", + "model_id": "ba853d0eedf54f0e90435e3abc73808d", "version_major": 2, "version_minor": 0 }, @@ -1485,13 +1008,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 572.17it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 578.61it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "353e25f670904737902e35bce2106796", + "model_id": "4f7a8691e6854a689583f18e24a8e471", "version_major": 2, "version_minor": 0 }, @@ -1506,13 +1029,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 574.02it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 585.03it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "f42e57286e6e4b0c9ebad592040dd6f2", + "model_id": "a44c7a68e0804ab48ac624af8005bc41", "version_major": 2, "version_minor": 0 }, @@ -1527,13 +1050,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 578.76it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 542.41it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "89da8094266f41e99e7ea660baf16279", + "model_id": "7d0cfc8a257d488faf9b9db092e20e3c", "version_major": 2, "version_minor": 0 }, @@ -1548,13 +1071,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 581.87it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 579.91it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "70efe8069b9d4f8cbbe1ed5fb9828102", + "model_id": "5cccd850bbfd479ebe99d51319cdbe05", "version_major": 2, "version_minor": 0 }, @@ -1569,13 +1092,13 @@ "name": "stderr", "output_type": "stream", "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 570.70it/s]\n" + "Creating sequence of samples: 100%|██████████| 560/560 [00:00<00:00, 587.27it/s]\n" ] }, { "data": { "application/vnd.jupyter.widget-view+json": { - "model_id": "1608c83b6eb4417a81632c67323f57c2", + "model_id": "9e4008ae66a54c57a0a7dc5beb1f9410", "version_major": 2, "version_minor": 0 }, @@ -1590,19 +1113,19 @@ "source": [ "protected_acc = []\n", "for eps in eps_space:\n", - " attacker = FGSMAttacker(model, eps=eps)\n", + " attacker = PGDAttacker(model, eps=eps)\n", " protected_acc.append(accuracy(attacker, defender, step_size=10))" ] }, { "cell_type": "code", - "execution_count": 10, + "execution_count": 12, "id": "eacd66d8-ea8e-46dc-a295-4ddb8f279820", "metadata": {}, "outputs": [ { "data": { - "image/png": "", + "image/png": "", "text/plain": [ "
" ] @@ -1622,9 +1145,51 @@ }, { "cell_type": "code", - "execution_count": null, + "execution_count": 10, "id": "10f99abc-9e65-49e5-96d8-788028ca2f72", "metadata": {}, + "outputs": [ + { + "name": "stderr", + "output_type": "stream", + "text": [ + "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 517.86it/s]\n" + ] + }, + { + "data": { + "application/vnd.jupyter.widget-view+json": { + "model_id": "d2e332308d6f4790bb53cee473d9fdf4", + "version_major": 2, + "version_minor": 0 + }, + "text/plain": [ + " 0%| | 0/2154 [00:00 Date: Fri, 28 Jun 2024 13:58:38 +0300 Subject: [PATCH 2/6] upd readme --- README.md | 106 ++++++++++++++++++++++++++++++++++++++++++++++++++---- 1 file changed, 99 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index a063ab7..047768a 100644 --- a/README.md +++ b/README.md @@ -1,18 +1,110 @@ -# Defense of adversarial attacks on FDD models +# FDD Defense: Adversarial Attacks and Defenses on Fault Diagnosis and Detection models -`fdd-defense` is a python library with adversarial attacks on Fault Detection and Diagnostic (FDD) models and defense methods against attacks. +## Introduction + +The development of the smart manufacturing trend includes the integration of Artificial Intelligence technologies into industrial processes. One example of such implementation is deep learning models that diagnose the current state of a technological process. Recent studies have demonstrated that small data perturbations, named adversarial attacks, can significantly affect the correct predictions of such models. This fact is critical in industrial systems, where AI-based decisions can be made to manage physical equipment. `fdd-defense` helps to evaluate the robustness of technological process diagnosis models to adversarial attacks, as well as consider defense methods. + +`fdd-defense` is a python library with adversarial attacks on Fault Detection and Diagnostic (FDD) models and defense methods against adversarial attacks. This repository contains the original implementation of methods from the paper [Adversarial Attacks and Defenses in Fault Detection and Diagnosis: A Comprehensive Benchmark on the Tennessee Eastman Process](https://ieeexplore.ieee.org/abstract/document/10531068). ## Installing -To install the library, go to the `fdd-defense` directory and run `pip` as follows +To install `fdd-defense`, run the following command: ``` -pip install -e . +pip install git+https://github.com/AIRI-Institute/fdd-defense.git ``` -## Testing +## Usage + +```python +from fdd_defense.models import MLP +from fdd_defense.attackers import FGSMAttacker +from fdd_defense.defenders import AdversarialTrainingDefender +from fdd_defense.utils import evaluate +from fddbenchmark import FDDDataset +from sklearn.preprocessing import StandardScaler + +# Download and scale the TEP dataset +dataset = FDDDataset(name='reinartz_tep') +scaler = StandardScaler() +scaler.fit(dataset.df[dataset.train_mask]) +dataset.df[:] = scaler.transform(dataset.df) + +# Define and train a FDD model +model = MLP( + window_size=50, + step_size=1, + device='cuda', + batch_size=128, + num_epochs=10 +) +model.fit(dataset) -To test the library, run +# Test the FDD model on original data without defense +defender = NoDefenceDefender(model) +attacker = NoAttacker(model, eps=epsilon) +accuracy = evaluate(defender, attacker) +print(f'Accuracy: {accuracy:.4f}') + +# Test the FDD model under FGSM attack without defense +defender = NoDefenceDefender(model) +attacker = FGSMAttacker(defender, eps=epsilon) +accuracy = evaluate(defender, attacker) +print(f'Accuracy: {accuracy:.4f}') + +# Test the FDD model under FGSM attack with Adversarial Training defense +defender = AdversarialTrainingDefender(model) +attacker = FGSMAttacker(defender, eps=epsilon) +accuracy = evaluate(defender, attacker) +print(f'Accuracy: {accuracy:.4f}') ``` -pytest tests + +## Implemented methods + +### FDD models + +| FDD model | Reference | +|-----------------|-----------| +| Linear |Pandya, D., Upadhyay, S. H., & Harsha, S. P. (2014). Fault diagnosis of rolling element bearing by using multinomial logistic regression and wavelet packet transform. Soft Computing, 18, 255-266.| +|Boosting |Ruder, Sebastian. "An overview of gradient descent optimization algorithms." arXiv preprint arXiv:1609.04747 (2016).| +| MLP |Khoualdia, T., Lakehal, A., Chelli, Z., Khoualdia, K., & Nessaib, K. (2021). Optimized multi layer perceptron artificial neural network based fault diagnosis of induction motor using vibration signals. Diagnostyka, 22.| +| GRU, TCN |Lomov, Ildar, et al. "Fault detection in Tennessee Eastman process with temporal deep learning models." Journal of Industrial Information Integration 23 (2021): 100216.| + +### Adversarial attacks + +| Adversarial attack | Reference | +|------------------------|-----------| +| Noise |Zhuo, Yue, Zhenqin Yin, and Zhiqiang Ge. "Attack and defense: Adversarial security of data-driven FDC systems." IEEE Transactions on Industrial Informatics 19.1 (2022): 5-19.| +| FGSM |Goodfellow, Ian J., Jonathon Shlens, and Christian Szegedy. "Explaining and harnessing adversarial examples." arXiv preprint arXiv:1412.6572 (2014).| +| PGD |Madry, Aleksander, et al. "Towards deep learning models resistant to adversarial attacks." arXiv preprint arXiv:1706.06083 (2017).| +| DeepFool |Moosavi-Dezfooli, Seyed-Mohsen, Alhussein Fawzi, and Pascal Frossard. "Deepfool: a simple and accurate method to fool deep neural networks." Proceedings of the IEEE conference on computer vision and pattern recognition. 2016.| +| Carlini & Wagner |Carlini, Nicholas, and David Wagner. "Towards evaluating the robustness of neural networks." 2017 ieee symposium on security and privacy (sp). Ieee, 2017.| +| Distillation black-box |Cui, Weiyu, et al. "Substitute model generation for black-box adversarial attack based on knowledge distillation." 2020 IEEE International Conference on Image Processing (ICIP). IEEE, 2020.| + +### Defense methods + +| Defense method | Reference | +|-------------------------|-----------| +| Adversarial training |Goodfellow, Ian J., Jonathon Shlens, and Christian Szegedy. "Explaining and harnessing adversarial examples." arXiv preprint arXiv:1412.6572 (2014).| +| Data quantization |Guo, Chuan, et al. "Countering adversarial images using input transformations." arXiv preprint arXiv:1711.00117 (2017).| +| Gradient regularization |Finlay, Chris, and Adam M. Oberman. "Scaleable input gradient regularization for adversarial robustness." Machine Learning with Applications 3 (2021): 100017.| +| Defensive distillation |Papernot, Nicolas, et al. "Distillation as a defense to adversarial perturbations against deep neural networks." 2016 IEEE symposium on security and privacy (SP). IEEE, 2016.| +| ATQ |Pozdnyakov, Vitaliy, et al. "Adversarial Attacks and Defenses in Fault Detection and Diagnosis: A Comprehensive Benchmark on the Tennessee Eastman Process." IEEE Open Journal of the Industrial Electronics Society (2024).| + +## Testing + +To test the library, run the command `pytest tests` from the root directory. + +## Citation + +Please cite our paper as follows: + ``` +@article{pozdnyakov2024adversarial, + title={Adversarial Attacks and Defenses in Fault Detection and Diagnosis: A Comprehensive Benchmark on the Tennessee Eastman Process}, + author={Pozdnyakov, Vitaliy and Kovalenko, Aleksandr and Makarov, Ilya and Drobyshevskiy, Mikhail and Lukyanov, Kirill}, + journal={IEEE Open Journal of the Industrial Electronics Society}, + year={2024}, + publisher={IEEE} +} +``` \ No newline at end of file From 794c647c6b0ee77936dedc5e58ca605b4efc37a1 Mon Sep 17 00:00:00 2001 From: Vitaliy Pozdnyakov Date: Wed, 24 Jul 2024 14:47:04 +0300 Subject: [PATCH 3/6] Update README.md --- README.md | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/README.md b/README.md index 047768a..1981004 100644 --- a/README.md +++ b/README.md @@ -17,9 +17,9 @@ pip install git+https://github.com/AIRI-Institute/fdd-defense.git ```python from fdd_defense.models import MLP -from fdd_defense.attackers import FGSMAttacker -from fdd_defense.defenders import AdversarialTrainingDefender -from fdd_defense.utils import evaluate +from fdd_defense.attackers import NoAttacker, FGSMAttacker +from fdd_defense.defenders import NoDefenceDefender, AdversarialTrainingDefender +from fdd_defense.utils import accuracy from fddbenchmark import FDDDataset from sklearn.preprocessing import StandardScaler @@ -40,22 +40,22 @@ model = MLP( model.fit(dataset) # Test the FDD model on original data without defense +attacker = NoAttacker(model, eps=0.05) defender = NoDefenceDefender(model) -attacker = NoAttacker(model, eps=epsilon) -accuracy = evaluate(defender, attacker) -print(f'Accuracy: {accuracy:.4f}') +acc = accuracy(attacker, defender, step_size=1) +print(f'Accuracy: {acc:.4f}') # Test the FDD model under FGSM attack without defense +attacker = FGSMAttacker(model, eps=0.05) defender = NoDefenceDefender(model) -attacker = FGSMAttacker(defender, eps=epsilon) -accuracy = evaluate(defender, attacker) -print(f'Accuracy: {accuracy:.4f}') +acc = accuracy(attacker, defender, step_size=1) +print(f'Accuracy: {acc:.4f}') # Test the FDD model under FGSM attack with Adversarial Training defense -defender = AdversarialTrainingDefender(model) -attacker = FGSMAttacker(defender, eps=epsilon) -accuracy = evaluate(defender, attacker) -print(f'Accuracy: {accuracy:.4f}') +attacker = FGSMAttacker(model, eps=0.05) +defender = AdversarialTrainingDefender(model, attacker) +acc = accuracy(attacker, defender, step_size=1) +print(f'Accuracy: {acc:.4f}') ``` @@ -107,4 +107,4 @@ Please cite our paper as follows: year={2024}, publisher={IEEE} } -``` \ No newline at end of file +``` From d23cfb892236fd1b9e846625edcb955012510d7b Mon Sep 17 00:00:00 2001 From: Vitaliy Pozdnyakov Date: Fri, 26 Jul 2024 18:18:56 +0300 Subject: [PATCH 4/6] Update README.md Fix the reference of data quantization --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 1981004..3be19c2 100644 --- a/README.md +++ b/README.md @@ -86,7 +86,7 @@ print(f'Accuracy: {acc:.4f}') | Defense method | Reference | |-------------------------|-----------| | Adversarial training |Goodfellow, Ian J., Jonathon Shlens, and Christian Szegedy. "Explaining and harnessing adversarial examples." arXiv preprint arXiv:1412.6572 (2014).| -| Data quantization |Guo, Chuan, et al. "Countering adversarial images using input transformations." arXiv preprint arXiv:1711.00117 (2017).| +| Data quantization |Xu, Weilin, David Evans, and Yanjun Qi. "Feature squeezing: Detecting adversarial examples in deep neural networks." arXiv preprint arXiv:1704.01155 (2017).| | Gradient regularization |Finlay, Chris, and Adam M. Oberman. "Scaleable input gradient regularization for adversarial robustness." Machine Learning with Applications 3 (2021): 100017.| | Defensive distillation |Papernot, Nicolas, et al. "Distillation as a defense to adversarial perturbations against deep neural networks." 2016 IEEE symposium on security and privacy (SP). IEEE, 2016.| | ATQ |Pozdnyakov, Vitaliy, et al. "Adversarial Attacks and Defenses in Fault Detection and Diagnosis: A Comprehensive Benchmark on the Tennessee Eastman Process." IEEE Open Journal of the Industrial Electronics Society (2024).| From 0a768b3257ecee8511b3cc7c0dbbf5f5a8b029d2 Mon Sep 17 00:00:00 2001 From: alex Date: Mon, 5 Aug 2024 08:43:28 +0300 Subject: [PATCH 5/6] n --- experiments.ipynb | 1218 --------------------------------------------- 1 file changed, 1218 deletions(-) delete mode 100644 experiments.ipynb diff --git a/experiments.ipynb b/experiments.ipynb deleted file mode 100644 index 9082c14..0000000 --- a/experiments.ipynb +++ /dev/null @@ -1,1218 +0,0 @@ -{ - "cells": [ - { - "cell_type": "code", - "execution_count": 1, - "id": "cee04ff8-462f-4d43-adf9-1596b44fbc6c", - "metadata": {}, - "outputs": [], - "source": [ - "import pandas as pd\n", - "import numpy as np\n", - "from sklearn.preprocessing import StandardScaler\n", - "from tqdm.auto import tqdm\n", - "import matplotlib.pyplot as plt\n", - "import torch\n", - "import warnings\n", - "warnings.filterwarnings('ignore')\n", - "\n", - "from fddbenchmark import FDDDataset, FDDDataloader, FDDEvaluator\n", - "\n", - "from fdd_defense.models import MLP, TCN, GRU\n", - "from fdd_defense.attackers import *\n", - "from fdd_defense.defenders import *\n", - "from fdd_defense.utils import accuracy" - ] - }, - { - "cell_type": "markdown", - "id": "83f1c191-a0c7-4bf1-9f83-8f479bedf28b", - "metadata": {}, - "source": [ - "### Dataset preparation\n", - "https://github.com/airi-industrial-ai/fddbenchmark.git - fdd benchmark with TEP dataset" - ] - }, - { - "cell_type": "code", - "execution_count": 2, - "id": "12038362-a880-4cd2-b559-84caaf731a91", - "metadata": {}, - "outputs": [ - { - "data": { - "application/vnd.jupyter.widget-view+json": { - "model_id": "4ba0e25c03f44c84845d4f2c50ad701a", - "version_major": 2, - "version_minor": 0 - }, - "text/plain": [ - "Reading data/small_tep/dataset.csv: 0%| | 0/153300 [00:00 6\u001b[0m unprotected_acc\u001b[38;5;241m.\u001b[39mappend(accuracy(attacker, defender, step_size\u001b[38;5;241m=\u001b[39m\u001b[38;5;241m10\u001b[39m))\n", - "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/utils.py:28\u001b[0m, in \u001b[0;36maccuracy\u001b[0;34m(attacker, defender, step_size)\u001b[0m\n\u001b[1;32m 26\u001b[0m pred \u001b[38;5;241m=\u001b[39m attacker\u001b[38;5;241m.\u001b[39mmodel\u001b[38;5;241m.\u001b[39mpredict(sample)\n\u001b[1;32m 27\u001b[0m adv_sample \u001b[38;5;241m=\u001b[39m attacker\u001b[38;5;241m.\u001b[39mattack(sample, pred)\n\u001b[0;32m---> 28\u001b[0m pred \u001b[38;5;241m=\u001b[39m defender\u001b[38;5;241m.\u001b[39mpredict(adv_sample)\n\u001b[1;32m 29\u001b[0m preds\u001b[38;5;241m.\u001b[39mappend(pred)\n\u001b[1;32m 30\u001b[0m labels\u001b[38;5;241m.\u001b[39mappend(label)\n", - "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/defenders/base.py:12\u001b[0m, in \u001b[0;36mBaseDefender.predict\u001b[0;34m(self, ts)\u001b[0m\n\u001b[1;32m 11\u001b[0m \u001b[38;5;28;01mdef\u001b[39;00m \u001b[38;5;21mpredict\u001b[39m(\u001b[38;5;28mself\u001b[39m, ts: np\u001b[38;5;241m.\u001b[39mndarray):\n\u001b[0;32m---> 12\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mmodel\u001b[38;5;241m.\u001b[39mpredict(ts)\n", - "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/base.py:80\u001b[0m, in \u001b[0;36mBaseTorchModel.predict\u001b[0;34m(self, ts)\u001b[0m\n\u001b[1;32m 78\u001b[0m ts \u001b[38;5;241m=\u001b[39m torch\u001b[38;5;241m.\u001b[39mFloatTensor(ts)\u001b[38;5;241m.\u001b[39mto(\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdevice)\n\u001b[1;32m 79\u001b[0m \u001b[38;5;28;01mwith\u001b[39;00m torch\u001b[38;5;241m.\u001b[39mno_grad():\n\u001b[0;32m---> 80\u001b[0m logits \u001b[38;5;241m=\u001b[39m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mmodel(ts)\n\u001b[1;32m 81\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m logits\u001b[38;5;241m.\u001b[39margmax(axis\u001b[38;5;241m=\u001b[39m\u001b[38;5;241m1\u001b[39m)\u001b[38;5;241m.\u001b[39mcpu()\u001b[38;5;241m.\u001b[39mnumpy()\n", - "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1511\u001b[0m, in \u001b[0;36mModule._wrapped_call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1509\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_compiled_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs) \u001b[38;5;66;03m# type: ignore[misc]\u001b[39;00m\n\u001b[1;32m 1510\u001b[0m \u001b[38;5;28;01melse\u001b[39;00m:\n\u001b[0;32m-> 1511\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n", - "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1520\u001b[0m, in \u001b[0;36mModule._call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1515\u001b[0m \u001b[38;5;66;03m# If we don't have any hooks, we want to skip the rest of the logic in\u001b[39;00m\n\u001b[1;32m 1516\u001b[0m \u001b[38;5;66;03m# this function, and just call forward.\u001b[39;00m\n\u001b[1;32m 1517\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;129;01mnot\u001b[39;00m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_pre_hooks\n\u001b[1;32m 1518\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_backward_hooks\n\u001b[1;32m 1519\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_forward_pre_hooks):\n\u001b[0;32m-> 1520\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m forward_call(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n\u001b[1;32m 1522\u001b[0m \u001b[38;5;28;01mtry\u001b[39;00m:\n\u001b[1;32m 1523\u001b[0m result \u001b[38;5;241m=\u001b[39m \u001b[38;5;28;01mNone\u001b[39;00m\n", - "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/tcn.py:195\u001b[0m, in \u001b[0;36mTCNModule.forward\u001b[0;34m(self, x)\u001b[0m\n\u001b[1;32m 193\u001b[0m x \u001b[38;5;241m=\u001b[39m x\u001b[38;5;241m.\u001b[39mtranspose(\u001b[38;5;241m1\u001b[39m, \u001b[38;5;241m2\u001b[39m)\n\u001b[1;32m 194\u001b[0m \u001b[38;5;28;01mfor\u001b[39;00m res_block \u001b[38;5;129;01min\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mres_blocks_list:\n\u001b[0;32m--> 195\u001b[0m x \u001b[38;5;241m=\u001b[39m res_block(x)\n\u001b[1;32m 196\u001b[0m x \u001b[38;5;241m=\u001b[39m x\u001b[38;5;241m.\u001b[39mtranspose(\u001b[38;5;241m1\u001b[39m, \u001b[38;5;241m2\u001b[39m)[:, \u001b[38;5;241m-\u001b[39m\u001b[38;5;241m1\u001b[39m, :]\n\u001b[1;32m 197\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m x\n", - "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1511\u001b[0m, in \u001b[0;36mModule._wrapped_call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1509\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_compiled_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs) \u001b[38;5;66;03m# type: ignore[misc]\u001b[39;00m\n\u001b[1;32m 1510\u001b[0m \u001b[38;5;28;01melse\u001b[39;00m:\n\u001b[0;32m-> 1511\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_call_impl(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n", - "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/modules/module.py:1520\u001b[0m, in \u001b[0;36mModule._call_impl\u001b[0;34m(self, *args, **kwargs)\u001b[0m\n\u001b[1;32m 1515\u001b[0m \u001b[38;5;66;03m# If we don't have any hooks, we want to skip the rest of the logic in\u001b[39;00m\n\u001b[1;32m 1516\u001b[0m \u001b[38;5;66;03m# this function, and just call forward.\u001b[39;00m\n\u001b[1;32m 1517\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;129;01mnot\u001b[39;00m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39m_forward_pre_hooks\n\u001b[1;32m 1518\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_backward_pre_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_backward_hooks\n\u001b[1;32m 1519\u001b[0m \u001b[38;5;129;01mor\u001b[39;00m _global_forward_hooks \u001b[38;5;129;01mor\u001b[39;00m _global_forward_pre_hooks):\n\u001b[0;32m-> 1520\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m forward_call(\u001b[38;5;241m*\u001b[39margs, \u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39mkwargs)\n\u001b[1;32m 1522\u001b[0m \u001b[38;5;28;01mtry\u001b[39;00m:\n\u001b[1;32m 1523\u001b[0m result \u001b[38;5;241m=\u001b[39m \u001b[38;5;28;01mNone\u001b[39;00m\n", - "File \u001b[0;32m~/work/github/attacks/fdd-defense/fdd_defense/models/tcn.py:98\u001b[0m, in \u001b[0;36mResidualBlock.forward\u001b[0;34m(self, x)\u001b[0m\n\u001b[1;32m 94\u001b[0m \u001b[38;5;66;03m# first step\u001b[39;00m\n\u001b[1;32m 95\u001b[0m left_padding \u001b[38;5;241m=\u001b[39m (\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdilation_base\u001b[38;5;241m*\u001b[39m\u001b[38;5;241m*\u001b[39m\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mnr_blocks_below) \u001b[38;5;241m*\u001b[39m (\n\u001b[1;32m 96\u001b[0m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mkernel_size \u001b[38;5;241m-\u001b[39m \u001b[38;5;241m1\u001b[39m\n\u001b[1;32m 97\u001b[0m )\n\u001b[0;32m---> 98\u001b[0m x \u001b[38;5;241m=\u001b[39m F\u001b[38;5;241m.\u001b[39mpad(x, (left_padding, \u001b[38;5;241m0\u001b[39m))\n\u001b[1;32m 99\u001b[0m x \u001b[38;5;241m=\u001b[39m \u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mdropout_fn(F\u001b[38;5;241m.\u001b[39mrelu(\u001b[38;5;28mself\u001b[39m\u001b[38;5;241m.\u001b[39mconv1(x)))\n\u001b[1;32m 101\u001b[0m \u001b[38;5;66;03m# second step\u001b[39;00m\n", - "File \u001b[0;32m~/anaconda3/lib/python3.11/site-packages/torch/nn/functional.py:4495\u001b[0m, in \u001b[0;36mpad\u001b[0;34m(input, pad, mode, value)\u001b[0m\n\u001b[1;32m 4488\u001b[0m \u001b[38;5;28;01mif\u001b[39;00m \u001b[38;5;28mlen\u001b[39m(pad) \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m4\u001b[39m \u001b[38;5;129;01mand\u001b[39;00m (\u001b[38;5;28minput\u001b[39m\u001b[38;5;241m.\u001b[39mdim() \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m3\u001b[39m \u001b[38;5;129;01mor\u001b[39;00m \u001b[38;5;28minput\u001b[39m\u001b[38;5;241m.\u001b[39mdim() \u001b[38;5;241m==\u001b[39m \u001b[38;5;241m4\u001b[39m) \u001b[38;5;129;01mand\u001b[39;00m mode \u001b[38;5;241m==\u001b[39m \u001b[38;5;124m'\u001b[39m\u001b[38;5;124mreplicate\u001b[39m\u001b[38;5;124m'\u001b[39m:\n\u001b[1;32m 4489\u001b[0m \u001b[38;5;66;03m# Use slow decomp whose backward will be in terms of index_put.\u001b[39;00m\n\u001b[1;32m 4490\u001b[0m \u001b[38;5;66;03m# importlib is required because the import cannot be top level\u001b[39;00m\n\u001b[1;32m 4491\u001b[0m \u001b[38;5;66;03m# (cycle) and cannot be nested (TS doesn't support)\u001b[39;00m\n\u001b[1;32m 4492\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m importlib\u001b[38;5;241m.\u001b[39mimport_module(\u001b[38;5;124m'\u001b[39m\u001b[38;5;124mtorch._decomp.decompositions\u001b[39m\u001b[38;5;124m'\u001b[39m)\u001b[38;5;241m.\u001b[39mreplication_pad2d(\n\u001b[1;32m 4493\u001b[0m \u001b[38;5;28minput\u001b[39m, pad\n\u001b[1;32m 4494\u001b[0m )\n\u001b[0;32m-> 4495\u001b[0m \u001b[38;5;28;01mreturn\u001b[39;00m torch\u001b[38;5;241m.\u001b[39m_C\u001b[38;5;241m.\u001b[39m_nn\u001b[38;5;241m.\u001b[39mpad(\u001b[38;5;28minput\u001b[39m, pad, mode, value)\n", - "\u001b[0;31mKeyboardInterrupt\u001b[0m: " - ] - } - ], - "source": [ - "eps_space = np.linspace(1e-6, 0.3, 20)\n", - "unprotected_acc = []\n", - "defender = NoDefenceDefender(model)\n", - "for eps in eps_space:\n", - " attacker = CarliniWagnerAttacker(model, eps=eps)\n", - " unprotected_acc.append(accuracy(attacker, defender, step_size=10))" - ] - }, - { - "cell_type": "code", - "execution_count": 6, - "id": "035a15eb-bff7-4aad-91af-563013d91f37", - "metadata": {}, - "outputs": [ - { - "data": { - "image/png": "", - "text/plain": [ - "
" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "plt.plot(eps_space, unprotected_acc)\n", - "plt.xlabel('eps')\n", - "plt.ylabel('accuracy')\n", - "plt.ylim(ymin=0,ymax=1)\n", - "plt.grid()\n", - "plt.show()" - ] - }, - { - "cell_type": "markdown", - "id": "4361e602-edc6-43a1-9442-db691a2ea148", - "metadata": {}, - "source": [ - "### Accuracy of the protected model under attack\n", - "defender -- can be selected from AdversarialTrainingDefender, QuantizationDefender, DistillationDefender, RegularizationDefender, AutoEncoderDefender and ATQDefender" - ] - }, - { - "cell_type": "code", - "execution_count": 7, - "id": "e65bff16-eba3-4193-9db4-0bcde5433bef", - "metadata": {}, - "outputs": [ - { - "name": "stdout", - "output_type": "stream", - "text": [ - "ATQ training...\n" - ] - }, - { - "data": { - "application/vnd.jupyter.widget-view+json": { - "model_id": "ebcb82357a4047b9a6782cb98feb2a3b", - "version_major": 2, - "version_minor": 0 - }, - "text/plain": [ - "Epochs ...: 0%| | 0/10 [00:00" - ] - }, - "metadata": {}, - "output_type": "display_data" - } - ], - "source": [ - "plt.plot(eps_space, protected_acc)\n", - "plt.xlabel('eps')\n", - "plt.ylabel('accuracy')\n", - "plt.ylim(ymin=0,ymax=1)\n", - "plt.grid()\n", - "plt.show()" - ] - }, - { - "cell_type": "code", - "execution_count": 10, - "id": "10f99abc-9e65-49e5-96d8-788028ca2f72", - "metadata": {}, - "outputs": [ - { - "name": "stderr", - "output_type": "stream", - "text": [ - "Creating sequence of samples: 100%|██████████| 560/560 [00:01<00:00, 517.86it/s]\n" - ] - }, - { - "data": { - "application/vnd.jupyter.widget-view+json": { - "model_id": "d2e332308d6f4790bb53cee473d9fdf4", - "version_major": 2, - "version_minor": 0 - }, - "text/plain": [ - " 0%| | 0/2154 [00:00 Date: Wed, 7 Aug 2024 11:23:58 +0300 Subject: [PATCH 6/6] notebook add comments --- experiments.ipynb | 1682 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 1682 insertions(+) create mode 100644 experiments.ipynb diff --git a/experiments.ipynb b/experiments.ipynb new file mode 100644 index 0000000..0a9489a --- /dev/null +++ b/experiments.ipynb @@ -0,0 +1,1682 @@ +{ + "cells": [ + { + "cell_type": "code", + "execution_count": 1, + "id": "cee04ff8-462f-4d43-adf9-1596b44fbc6c", + "metadata": {}, + "outputs": [], + "source": [ + "import pandas as pd\n", + "import numpy as np\n", + "from sklearn.preprocessing import StandardScaler\n", + "from tqdm.auto import tqdm\n", + "import matplotlib.pyplot as plt\n", + "import torch\n", + "import warnings\n", + "warnings.filterwarnings('ignore')\n", + "\n", + "from fddbenchmark import FDDDataset, FDDDataloader, FDDEvaluator\n", + "\n", + "from fdd_defense.models import MLP, TCN, GRU\n", + "from fdd_defense.attackers import *\n", + "from fdd_defense.defenders import *\n", + "from fdd_defense.utils import accuracy" + ] + }, + { + "cell_type": "markdown", + "id": "83f1c191-a0c7-4bf1-9f83-8f479bedf28b", + "metadata": {}, + "source": [ + "### Dataset preparation\n", + "https://github.com/airi-industrial-ai/fddbenchmark.git - fdd benchmark with TEP dataset" + ] + }, + { + "cell_type": "code", + "execution_count": 2, + "id": "12038362-a880-4cd2-b559-84caaf731a91", + "metadata": {}, + "outputs": [ + { + "data": { + "application/vnd.jupyter.widget-view+json": { + "model_id": "d0134859afbb428a9d26bd2d28f879d6", + "version_major": 2, + "version_minor": 0 + }, + "text/plain": [ + "Reading data/reinartz_tep/dataset.csv: 0%| | 0/5600000 [00:00" + ] + }, + "metadata": {}, + "output_type": "display_data" + } + ], + "source": [ + "plt.plot(eps_space, unprotected_acc)\n", + "plt.xlabel('eps')\n", + "plt.ylabel('accuracy')\n", + "plt.ylim(ymin=0,ymax=1)\n", + "plt.grid()\n", + "plt.show()" + ] + }, + { + "cell_type": "markdown", + "id": "4361e602-edc6-43a1-9442-db691a2ea148", + "metadata": {}, + "source": [ + "### Accuracy of the protected model under attack\n", + "defender -- can be selected from AdversarialTrainingDefender, QuantizationDefender, DistillationDefender, RegularizationDefender, AutoEncoderDefender and ATQDefender" + ] + }, + { + "cell_type": "code", + "execution_count": 8, + "id": "e65bff16-eba3-4193-9db4-0bcde5433bef", + "metadata": {}, + "outputs": [ + { + "name": "stdout", + "output_type": "stream", + "text": [ + "ATQ training...\n" + ] + }, + { + "data": { + "application/vnd.jupyter.widget-view+json": { + "model_id": "2c8e40bc2f864384857f1fbdd6055826", + "version_major": 2, + "version_minor": 0 + }, + "text/plain": [ + "Epochs ...: 0%| | 0/10 [00:00" + ] + }, + "metadata": {}, + "output_type": "display_data" + } + ], + "source": [ + "plt.plot(eps_space, protected_acc)\n", + "plt.xlabel('eps')\n", + "plt.ylabel('accuracy')\n", + "plt.ylim(ymin=0,ymax=1)\n", + "plt.grid()\n", + "plt.show()" + ] + }, + { + "cell_type": "code", + "execution_count": null, + "id": "10f99abc-9e65-49e5-96d8-788028ca2f72", + "metadata": {}, + "outputs": [], + "source": [] + } + ], + "metadata": { + "kernelspec": { + "display_name": "Python 3 (ipykernel)", + "language": "python", + "name": "python3" + }, + "language_info": { + "codemirror_mode": { + "name": "ipython", + "version": 3 + }, + "file_extension": ".py", + "mimetype": "text/x-python", + "name": "python", + "nbconvert_exporter": "python", + "pygments_lexer": "ipython3", + "version": "3.11.7" + } + }, + "nbformat": 4, + "nbformat_minor": 5 +}