import torch
import torch.nn as nn
import numpy as np

from .attack import Attack

from loss.WACELoss import WACELoss
from loss.WA_EFCE_nT_loss import WAEFCEnTLoss

class QSINIFGSM(Attack):
    r"""
    Q-SI-NI-FGSM in the paper 'NESTEROV ACCELERATED GRADIENT AND SCALEINVARIANCE FOR ADVERSARIAL ATTACKS'
    [https://arxiv.org/abs/1908.06281], Published as a conference paper at ICLR 2020
    Modified from "https://github.com/JHL-HUST/SI-NI-FGSM"

    Distance Measure : Linf

    Arguments:
        model (nn.Module): model to attack.
        eps (float): maximum perturbation. (Default: 8/255)
        alpha (float): step size. (Default: 2/255)
        decay (float): momentum factor. (Default: 1.0)
        steps (int): number of iterations. (Default: 5)
        m (int): number of scale copies. (Default: 5)

    Shape:
        - images: :math:`(N, C, H, W)` where `N = number of batches`, `C = number of channels`,        `H = height` and `W = width`. It must have a range [0, 1].
        - labels: :math:`(N)` where each value :math:`y_i` is :math:`0 \leq y_i \leq` `number of labels`.
        - output: :math:`(N, C, H, W)`.

    Examples::
        >>> attack = torchattacks.QSINIFGSM(model, eps=8/255, alpha=2/255, steps=5, decay=1.0, m=5)
        >>> adv_images = attack(images, labels)

    """

    def __init__(self, model, eps=8/255, alpha=2/255, steps=5, decay=1.0, m=5, victim_model=None, num_classes=10, wtop_n=1, query_num=1, loss_type='WACE', temperature_scale=1.0, fuzzy_scale=1.0):
        super().__init__("QSINIFGSM", model)
        self.eps = eps
        self.steps = steps
        self.decay = decay
        self.alpha = alpha
        self.m = m
        self._supported_mode = ['default', 'targeted']
        self.victim_model = victim_model
        self.num_classes = num_classes
        self.wtop_n = wtop_n
        self.query_num = query_num
        self.loss_type = loss_type
        self.temperature_scale = temperature_scale
        self.fuzzy_scale = fuzzy_scale

        # 根据self.steps和self.query_num确定需要查询victim model的位置，采取等距查询的方式
        assert self.query_num > 0 and self.query_num <= self.steps
        self.query_position = [int(np.floor(self.steps / self.query_num) * i) for i in range(self.query_num)]

    def forward(self, images, labels):
        r"""
        Overridden.
        """
        images = images.clone().detach().to(self.device)
        labels = labels.clone().detach().to(self.device)

        if self._targeted:
            target_labels = self._get_target_label(images, labels)


        momentum = torch.zeros_like(images).detach().to(self.device)

        if self.loss_type == 'WACE':
            loss = WACELoss(topn=self.wtop_n, num_classes=self.num_classes)
        elif self.loss_type == 'WAEFCEnT':
            loss = WAEFCEnTLoss(topn=self.wtop_n, num_classes=self.num_classes, temperature_scale=self.temperature_scale, fuzzy_scale=self.fuzzy_scale)

        adv_images = images.clone().detach()

        outputs_victim = None
        for _ in range(self.steps):
            adv_images.requires_grad = True
            nes_image = adv_images + self.decay*self.alpha*momentum
            # Calculate sum the gradients over the scale copies of the input image
            adv_grad = torch.zeros_like(images).detach().to(self.device)
            # 受害者模型查询
            if _ in self.query_position:
                with torch.no_grad():
                    outputs_victim = self.victim_model(adv_images)
            for i in torch.arange(self.m):
                nes_images = nes_image / torch.pow(2, i)
                outputs = self.model(nes_images)
                # Calculate loss
                if self._targeted:
                    cost = loss(outputs, labels, outputs_victim, targeted=True, target_labels=target_labels)
                else:
                    cost = loss(outputs, labels, outputs_victim)
                adv_grad += torch.autograd.grad(cost, adv_images,
                                                retain_graph=False, create_graph=False)[0]
            adv_grad = adv_grad / self.m

            # Update adversarial images
            grad = self.decay*momentum + adv_grad / torch.mean(torch.abs(adv_grad), dim=(1,2,3), keepdim=True)
            momentum = grad
            adv_images = adv_images.detach() + self.alpha*grad.sign()
            delta = torch.clamp(adv_images - images, min=-self.eps, max=self.eps)
            adv_images = torch.clamp(images + delta, min=0, max=1).detach()

        if self._targeted:
            return adv_images, target_labels
        else:
            return adv_images