{
  "_comment": "PGD ATTACK AGAINST CLASSIFIER, FOLLOWED BY PURIFICATION + CLASSIFICATION EVAL",
  "_comment": "------------------------------------------------------------------------------",
  "_comment": "===== EXPERIMENT PARAMETERS =====",
  "_comment": "type of data for experiment (cifar10, cifar100, svhn)",
  "data_type": "cifar10",
  "_comment": "name for experiment folder",
  "exp_dir": "out_attack/pgd_clf_transfer/",
  "_comment": "number of images for each attack batch",
  "batch_size": 10,
  "_comment": "first batch from test set to attack",
  "start_batch": 1,
  "_comment": "final batch from test set to attack",
  "end_batch": 50,
  "_comment": "use random images for subset or not",
  "subset_shuffle": true,
  "_comment": "seed for random numbers",
  "seed": 123,
  "_comment": "===== CLASSIFIER AND ENERGY NETWORKS =====",
  "_comment": "location of clf trained weights",
  "clf_weight_path": "./net_weights/clf.pth",
  "_comment": "location of ebm trained weights",
  "ebm_weight_path": "./net_weights/ebm.pth",
  "_comment": "===== ATTACK PARAMETERS =====",
  "_comment": "l_p norm for attack (use l_inf or l_2)",
  "adv_norm": "l_inf",
  "_comment": "number of attack steps",
  "adv_steps": 50,
  "_comment": "l_p ball size of image perturbation for pixels in [0, 255]",
  "adv_eps": 8.0,
  "_comment": "gradient step size in l_p norm of adv. update for pixels in [0, 255]",
  "adv_eta": 2.0,
  "_comment": "use random start in l_p ball around images (otherwise start at original image)",
  "adv_rand_start": true,
  "_comment": "use BPDA + EOT attack against purifier and classifier or get attack grads from classifier only",
  "use_bpda_eot": false,
  "_comment": "number parallel samples for EOT attack (==1 for non-eot attack, >1 for eot attack)",
  "eot_attack_reps": 15,
  "_comment": "method for averaging the output of parallel chains for EOT attack",
  "eot_attack_ave": "logits",
  "_comment": "===== PURIFICATION PARAMETERS =====",
  "_comment": "number of purification steps (0 for attack vs. classifier only)",
  "langevin_steps": 1500,
  "_comment": "langevin noise magnitude",
  "langevin_eps": 1e-2,
  "_comment": "number of parallel purification trials for verifying successful attacks with EOT defense",
  "eot_defense_reps": 150,
  "_comment": "method for averaging the output of parallel chains for EOT defense prediction",
  "eot_defense_ave": "logits",
  "_comment": "===== LOGGING =====",
  "_comment": "frequency of printing attack results",
  "log_freq": 5
}
