3 ms·
“ART provides tools that enable developers and researchers to defend and evaluate their ML models and applications against a number of adversarial threats, such
by Nbox9 5y ago
“ART provides tools that enable developers and researchers to defend and evaluate their ML models and applications against a number of adversarial threats, such as evasion, poisoning, extraction, and inference.”
The first two attacks, evasion & poisoning highlight the incredible importance of having high quality data when training models. Evasion is false-negatives that are allowed because the model did not have a diverse enough selection of training data and poisoning can occur when the data sources are not well vetted. Data quality is probably the single biggest problem with ML models, and I wish we’d see more of a focus on it.
- orange3xchicken 5y agoI'm less familiar with poisoning, but at least for test-time robustness, the current benchmark for image classifiers is AutoAttack [0,1]. It's an ensemble of adaptive & parameter-free gradient-based white-box and gradient-free black-box attacks. Submitted academic work is typically considered incomplete without an evaluation on AA (and sometimes deepfool [2]). It's good to see that both are included in ART. [0] https://arxiv.org/abs/2003.01690 https://arxiv.org/abs/2003.01690 [1] https://github.com/fra31/auto-attack https://github.com/fra31/auto-attack [2] https://arxiv.org/abs/1511.04599 https://arxiv.org/abs/1511.04599