

<!DOCTYPE html>
<html class="writer-html5" lang="en" >
<head>
  <meta charset="utf-8">
  
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  
  <title>deeprobust.image.attack.cw &mdash; DeepRobust 0.1.1 documentation</title>
  

  
  <link rel="stylesheet" href="../../../../_static/css/theme.css" type="text/css" />
  <link rel="stylesheet" href="../../../../_static/pygments.css" type="text/css" />

  
  
  
  

  
  <!--[if lt IE 9]>
    <script src="../../../../_static/js/html5shiv.min.js"></script>
  <![endif]-->
  
    
      <script type="text/javascript" id="documentation_options" data-url_root="../../../../" src="../../../../_static/documentation_options.js"></script>
        <script type="text/javascript" src="../../../../_static/jquery.js"></script>
        <script type="text/javascript" src="../../../../_static/underscore.js"></script>
        <script type="text/javascript" src="../../../../_static/doctools.js"></script>
        <script type="text/javascript" src="../../../../_static/language_data.js"></script>
        <script async="async" type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.5/latest.js?config=TeX-AMS-MML_HTMLorMML"></script>
    
    <script type="text/javascript" src="../../../../_static/js/theme.js"></script>

    
    <link rel="index" title="Index" href="../../../../genindex.html" />
    <link rel="search" title="Search" href="../../../../search.html" /> 
</head>

<body class="wy-body-for-nav">

   
  <div class="wy-grid-for-nav">
    
    <nav data-toggle="wy-nav-shift" class="wy-nav-side">
      <div class="wy-side-scroll">
        <div class="wy-side-nav-search" >
          

          
            <a href="../../../../index.html" class="icon icon-home" alt="Documentation Home"> DeepRobust
          

          
          </a>

          
            
            
          

          
<div role="search">
  <form id="rtd-search-form" class="wy-form" action="../../../../search.html" method="get">
    <input type="text" name="q" placeholder="Search docs" />
    <input type="hidden" name="check_keywords" value="yes" />
    <input type="hidden" name="area" value="default" />
  </form>
</div>

          
        </div>

        
        <div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
          
            
            
              
            
            
              <p class="caption"><span class="caption-text">Installation</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../notes/installation.html">Installation</a></li>
</ul>
<p class="caption"><span class="caption-text">Graph Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/data.html">Graph Dataset</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/attack.html">Introduction to Graph Attack with Examples</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/defense.html">Introduction to Graph Defense with Examples</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/pyg.html">Using PyTorch Geometric in DeepRobust</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/node_embedding.html">Node Embedding Attack and Defense</a></li>
</ul>
<p class="caption"><span class="caption-text">Image Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../image/example.html">Image Attack and Defense</a></li>
</ul>
<p class="caption"><span class="caption-text">Image Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.attack.html">deeprobust.image.attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.defense.html">deeprobust.image.defense package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.netmodels.html">deeprobust.image.netmodels package</a></li>
</ul>
<p class="caption"><span class="caption-text">Graph Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.global_attack.html">deeprobust.graph.global_attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.targeted_attack.html">deeprobust.graph.targeted_attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.defense.html">deeprobust.graph.defense package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.data.html">deeprobust.graph.data package</a></li>
</ul>

            
          
        </div>
        
      </div>
    </nav>

    <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">

      
      <nav class="wy-nav-top" aria-label="top navigation">
        
          <i data-toggle="wy-nav-top" class="fa fa-bars"></i>
          <a href="../../../../index.html">DeepRobust</a>
        
      </nav>


      <div class="wy-nav-content">
        
        <div class="rst-content">
        
          















<div role="navigation" aria-label="breadcrumbs navigation">

  <ul class="wy-breadcrumbs">
    
      <li><a href="../../../../index.html" class="icon icon-home"></a> &raquo;</li>
        
          <li><a href="../../../index.html">Module code</a> &raquo;</li>
        
      <li>deeprobust.image.attack.cw</li>
    
    
      <li class="wy-breadcrumbs-aside">
        
      </li>
    
  </ul>

  
  <hr/>
</div>
          <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
           <div itemprop="articleBody">
            
  <h1>Source code for deeprobust.image.attack.cw</h1><div class="highlight"><pre>
<span></span><span class="kn">import</span> <span class="nn">torch</span>
<span class="kn">from</span> <span class="nn">torch</span> <span class="kn">import</span> <span class="n">optim</span>
<span class="kn">import</span> <span class="nn">torch.nn</span> <span class="k">as</span> <span class="nn">nn</span>
<span class="kn">import</span> <span class="nn">numpy</span> <span class="k">as</span> <span class="nn">np</span>
<span class="kn">import</span> <span class="nn">logging</span>

<span class="kn">from</span> <span class="nn">deeprobust.image.attack.base_attack</span> <span class="kn">import</span> <span class="n">BaseAttack</span>
<span class="kn">from</span> <span class="nn">deeprobust.image.utils</span> <span class="kn">import</span> <span class="n">onehot_like</span>
<span class="kn">from</span> <span class="nn">deeprobust.image.optimizer</span> <span class="kn">import</span> <span class="n">AdamOptimizer</span>

<div class="viewcode-block" id="CarliniWagner"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner">[docs]</a><span class="k">class</span> <span class="nc">CarliniWagner</span><span class="p">(</span><span class="n">BaseAttack</span><span class="p">):</span>
    <span class="sd">&quot;&quot;&quot;</span>
<span class="sd">    C&amp;W attack is an effective method to calcuate high-confidence adversarial examples.</span>

<span class="sd">    References</span>
<span class="sd">    ----------</span>
<span class="sd">    .. [1] Carlini, N., &amp; Wagner, D. (2017, May). Towards evaluating the robustness of neural networks. https://arxiv.org/pdf/1608.04644.pdf</span>

<span class="sd">    This reimplementation is based on https://github.com/kkew3/pytorch-cw2</span>
<span class="sd">    Copyright 2018 Kaiwen Wu</span>

<span class="sd">    Examples</span>
<span class="sd">    --------</span>

<span class="sd">    &gt;&gt;&gt; from deeprobust.image.attack.cw import CarliniWagner</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.image.netmodels.CNN import Net</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.image.config import attack_params</span>

<span class="sd">    &gt;&gt;&gt; model = Net()</span>
<span class="sd">    &gt;&gt;&gt; model.load_state_dict(torch.load(&quot;./trained_models/MNIST_CNN_epoch_20.pt&quot;, map_location = torch.device(&#39;cuda&#39;)))</span>
<span class="sd">    &gt;&gt;&gt; model.eval()</span>

<span class="sd">    &gt;&gt;&gt; x,y = datasets.MNIST()</span>
<span class="sd">    &gt;&gt;&gt; attack = CarliniWagner(model, device=&#39;cuda&#39;)</span>
<span class="sd">    &gt;&gt;&gt; AdvExArray = attack.generate(x, y, target_label = 1, classnum = 10, **attack_params[&#39;CW_MNIST])</span>

<span class="sd">    &quot;&quot;&quot;</span>


    <span class="k">def</span> <span class="fm">__init__</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">model</span><span class="p">,</span> <span class="n">device</span> <span class="o">=</span> <span class="s1">&#39;cuda&#39;</span><span class="p">):</span>
        <span class="nb">super</span><span class="p">(</span><span class="n">CarliniWagner</span><span class="p">,</span> <span class="bp">self</span><span class="p">)</span><span class="o">.</span><span class="fm">__init__</span><span class="p">(</span><span class="n">model</span><span class="p">,</span> <span class="n">device</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">model</span> <span class="o">=</span> <span class="n">model</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">device</span> <span class="o">=</span> <span class="n">device</span>

<div class="viewcode-block" id="CarliniWagner.generate"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner.generate">[docs]</a>    <span class="k">def</span> <span class="nf">generate</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">image</span><span class="p">,</span> <span class="n">label</span><span class="p">,</span> <span class="n">target_label</span><span class="p">,</span> <span class="o">**</span><span class="n">kwargs</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;</span>
<span class="sd">        Call this function to generate adversarial examples.</span>

<span class="sd">        Parameters</span>
<span class="sd">        ----------</span>
<span class="sd">        image :</span>
<span class="sd">            original image</span>
<span class="sd">        label :</span>
<span class="sd">            target label</span>
<span class="sd">        kwargs :</span>
<span class="sd">            user defined paremeters</span>
<span class="sd">        &quot;&quot;&quot;</span>

        <span class="k">assert</span> <span class="bp">self</span><span class="o">.</span><span class="n">check_type_device</span><span class="p">(</span><span class="n">image</span><span class="p">,</span> <span class="n">label</span><span class="p">)</span>
        <span class="k">assert</span> <span class="bp">self</span><span class="o">.</span><span class="n">parse_params</span><span class="p">(</span><span class="o">**</span><span class="n">kwargs</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">target</span> <span class="o">=</span> <span class="n">target_label</span>
        <span class="k">return</span> <span class="bp">self</span><span class="o">.</span><span class="n">cw</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">model</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">image</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">label</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">target</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">confidence</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">max_iterations</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">initial_const</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">binary_search_steps</span><span class="p">,</span>
                  <span class="bp">self</span><span class="o">.</span><span class="n">learning_rate</span>
                  <span class="p">)</span></div>

<div class="viewcode-block" id="CarliniWagner.parse_params"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner.parse_params">[docs]</a>    <span class="k">def</span> <span class="nf">parse_params</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span>
                     <span class="n">classnum</span> <span class="o">=</span> <span class="mi">10</span><span class="p">,</span>
                     <span class="n">confidence</span> <span class="o">=</span> <span class="mf">1e-4</span><span class="p">,</span>
                     <span class="n">clip_max</span> <span class="o">=</span> <span class="mi">1</span><span class="p">,</span>
                     <span class="n">clip_min</span> <span class="o">=</span> <span class="mi">0</span><span class="p">,</span>
                     <span class="n">max_iterations</span> <span class="o">=</span> <span class="mi">1000</span><span class="p">,</span>
                     <span class="n">initial_const</span> <span class="o">=</span> <span class="mf">1e-2</span><span class="p">,</span>
                     <span class="n">binary_search_steps</span> <span class="o">=</span> <span class="mi">5</span><span class="p">,</span>
                     <span class="n">learning_rate</span> <span class="o">=</span> <span class="mf">0.00001</span><span class="p">,</span>
                     <span class="n">abort_early</span> <span class="o">=</span> <span class="kc">True</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;</span>
<span class="sd">        Parse the user defined parameters.</span>

<span class="sd">        Parameters</span>
<span class="sd">        ----------</span>
<span class="sd">        classnum :</span>
<span class="sd">            number of class</span>
<span class="sd">        confidence :</span>
<span class="sd">            confidence</span>
<span class="sd">        clip_max :</span>
<span class="sd">            maximum pixel value</span>
<span class="sd">        clip_min :</span>
<span class="sd">            minimum pixel value</span>
<span class="sd">        max_iterations :</span>
<span class="sd">            maximum number of iterations</span>
<span class="sd">        initial_const :</span>
<span class="sd">            initialization of binary search</span>
<span class="sd">        binary_search_steps :</span>
<span class="sd">            step number of binary search</span>
<span class="sd">        learning_rate :</span>
<span class="sd">            learning rate</span>
<span class="sd">        abort_early :</span>
<span class="sd">            Set abort_early = True to allow early stop</span>
<span class="sd">        &quot;&quot;&quot;</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">classnum</span> <span class="o">=</span> <span class="n">classnum</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">confidence</span> <span class="o">=</span> <span class="n">confidence</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span> <span class="o">=</span> <span class="n">clip_max</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span> <span class="o">=</span> <span class="n">clip_min</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">max_iterations</span> <span class="o">=</span> <span class="n">max_iterations</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">initial_const</span> <span class="o">=</span> <span class="n">initial_const</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">binary_search_steps</span> <span class="o">=</span> <span class="n">binary_search_steps</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">learning_rate</span> <span class="o">=</span> <span class="n">learning_rate</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">abort_early</span> <span class="o">=</span> <span class="n">abort_early</span>
        <span class="k">return</span> <span class="kc">True</span></div>

    <span class="k">def</span> <span class="nf">cw</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">model</span><span class="p">,</span> <span class="n">image</span><span class="p">,</span> <span class="n">label</span><span class="p">,</span> <span class="n">target</span><span class="p">,</span> <span class="n">confidence</span><span class="p">,</span> <span class="n">clip_max</span><span class="p">,</span> <span class="n">clip_min</span><span class="p">,</span> <span class="n">max_iterations</span><span class="p">,</span> <span class="n">initial_const</span><span class="p">,</span> <span class="n">binary_search_steps</span><span class="p">,</span> <span class="n">learning_rate</span><span class="p">):</span>
        <span class="c1">#change the input image</span>
        <span class="n">img_tanh</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">to_attack_space</span><span class="p">(</span><span class="n">image</span><span class="o">.</span><span class="n">cpu</span><span class="p">())</span>
        <span class="n">img_ori</span> <span class="p">,</span><span class="n">_</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">to_model_space</span><span class="p">(</span><span class="n">img_tanh</span><span class="p">)</span>
        <span class="n">img_ori</span> <span class="o">=</span> <span class="n">img_ori</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>

        <span class="c1">#binary search initialization</span>
        <span class="n">c</span> <span class="o">=</span> <span class="n">initial_const</span>
        <span class="n">c_low</span> <span class="o">=</span> <span class="mi">0</span>
        <span class="n">c_high</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">inf</span>
        <span class="n">found_adv</span> <span class="o">=</span> <span class="kc">False</span>
        <span class="n">last_loss</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">inf</span>

        <span class="k">for</span> <span class="n">step</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="n">binary_search_steps</span><span class="p">):</span>

            <span class="c1">#initialize w : perturbed image in tanh space</span>
            <span class="n">w</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">img_tanh</span><span class="o">.</span><span class="n">numpy</span><span class="p">())</span>

            <span class="n">optimizer</span> <span class="o">=</span> <span class="n">AdamOptimizer</span><span class="p">(</span><span class="n">img_tanh</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span>

            <span class="n">is_adversarial</span> <span class="o">=</span> <span class="kc">False</span>

            <span class="k">for</span> <span class="n">iteration</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="n">max_iterations</span><span class="p">):</span>

                <span class="c1"># adversary example</span>
                <span class="n">img_adv</span><span class="p">,</span> <span class="n">adv_grid</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">to_model_space</span><span class="p">(</span><span class="n">w</span><span class="p">)</span>
                <span class="n">img_adv</span> <span class="o">=</span> <span class="n">img_adv</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
                <span class="n">img_adv</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>

                <span class="c1">#output of the layer before softmax</span>
                <span class="n">output</span> <span class="o">=</span> <span class="n">model</span><span class="o">.</span><span class="n">get_logits</span><span class="p">(</span><span class="n">img_adv</span><span class="p">)</span>

                <span class="c1">#pending success</span>
                <span class="n">is_adversarial</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">pending_f</span><span class="p">(</span><span class="n">img_adv</span><span class="p">)</span>

                <span class="c1">#calculate loss function and gradient of loss funcition on x</span>
                <span class="n">loss</span><span class="p">,</span> <span class="n">loss_grad</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">loss_function</span><span class="p">(</span>
                    <span class="n">img_adv</span><span class="p">,</span> <span class="n">c</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">target</span><span class="p">,</span> <span class="n">img_ori</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">confidence</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span>
                <span class="p">)</span>


                <span class="c1">#calculate gradient of loss function on w</span>
                <span class="n">gradient</span> <span class="o">=</span> <span class="n">adv_grid</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span> <span class="o">*</span> <span class="n">loss_grad</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
                <span class="n">w</span> <span class="o">=</span> <span class="n">w</span> <span class="o">+</span> <span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">optimizer</span><span class="p">(</span><span class="n">gradient</span><span class="o">.</span><span class="n">cpu</span><span class="p">()</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span><span class="o">.</span><span class="n">numpy</span><span class="p">(),</span> <span class="n">learning_rate</span><span class="p">))</span><span class="o">.</span><span class="n">float</span><span class="p">()</span>

                <span class="k">if</span> <span class="n">is_adversarial</span><span class="p">:</span>
                    <span class="n">found_adv</span> <span class="o">=</span> <span class="kc">True</span>

            <span class="c1">#do binary search on c</span>
            <span class="k">if</span> <span class="n">found_adv</span><span class="p">:</span>
                <span class="n">c_high</span> <span class="o">=</span> <span class="n">c</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">c_low</span> <span class="o">=</span> <span class="n">c</span>

            <span class="k">if</span> <span class="n">c_high</span> <span class="o">==</span> <span class="n">np</span><span class="o">.</span><span class="n">inf</span><span class="p">:</span>
                <span class="n">c</span> <span class="o">*=</span> <span class="mi">10</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">c</span> <span class="o">=</span> <span class="p">(</span><span class="n">c_high</span> <span class="o">+</span> <span class="n">c_low</span><span class="p">)</span> <span class="o">/</span> <span class="mi">2</span>

            <span class="k">if</span> <span class="p">(</span><span class="n">step</span> <span class="o">%</span> <span class="mi">10</span> <span class="o">==</span> <span class="mi">0</span><span class="p">):</span>
                <span class="nb">print</span><span class="p">(</span><span class="s2">&quot;iteration:</span><span class="si">{:.0f}</span><span class="s2">,loss:</span><span class="si">{:.4f}</span><span class="s2">&quot;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">step</span><span class="p">,</span><span class="n">loss</span><span class="p">))</span>

            <span class="c1"># if (step == 50):</span>
            <span class="c1">#     learning_rate = learning_rate/100</span>

            <span class="c1">#abort early</span>
            <span class="k">if</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">abort_early</span> <span class="o">==</span> <span class="kc">True</span> <span class="ow">and</span> <span class="p">(</span><span class="n">step</span> <span class="o">%</span> <span class="mi">10</span><span class="p">)</span> <span class="o">==</span> <span class="mi">0</span> <span class="ow">and</span> <span class="n">step</span> <span class="o">&gt;</span> <span class="mi">100</span><span class="p">)</span> <span class="p">:</span>
                <span class="nb">print</span><span class="p">(</span><span class="s2">&quot;early abortion?&quot;</span><span class="p">,</span> <span class="n">loss</span><span class="p">,</span> <span class="n">last_loss</span><span class="p">)</span>
                <span class="k">if</span> <span class="ow">not</span> <span class="p">(</span><span class="n">loss</span> <span class="o">&lt;=</span> <span class="mf">0.9999</span> <span class="o">*</span> <span class="n">last_loss</span><span class="p">):</span>
                    <span class="k">break</span>
                <span class="n">last_loss</span> <span class="o">=</span> <span class="n">loss</span>


        <span class="k">return</span> <span class="n">img_adv</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>

<div class="viewcode-block" id="CarliniWagner.loss_function"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner.loss_function">[docs]</a>    <span class="k">def</span> <span class="nf">loss_function</span><span class="p">(</span>
        <span class="bp">self</span><span class="p">,</span> <span class="n">x_p</span><span class="p">,</span> <span class="n">const</span><span class="p">,</span> <span class="n">target</span><span class="p">,</span> <span class="n">reconstructed_original</span><span class="p">,</span> <span class="n">confidence</span><span class="p">,</span> <span class="n">min_</span><span class="p">,</span> <span class="n">max_</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;Returns the loss and the gradient of the loss w.r.t. x,</span>
<span class="sd">        assuming that logits = model(x).&quot;&quot;&quot;</span>

        <span class="c1">## get the output of model before softmax</span>
        <span class="n">x_p</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>
        <span class="n">logits</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">model</span><span class="o">.</span><span class="n">get_logits</span><span class="p">(</span><span class="n">x_p</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>

        <span class="c1">## find the largest class except the target class</span>
        <span class="n">targetlabel_mask</span> <span class="o">=</span> <span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">onehot_like</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">classnum</span><span class="p">),</span> <span class="n">target</span><span class="p">)))</span><span class="o">.</span><span class="n">double</span><span class="p">()</span>
        <span class="n">secondlargest_mask</span> <span class="o">=</span> <span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">ones</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">classnum</span><span class="p">))</span> <span class="o">-</span> <span class="n">targetlabel_mask</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>

        <span class="n">secondlargest</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">argmax</span><span class="p">((</span><span class="n">logits</span><span class="o">.</span><span class="n">double</span><span class="p">()</span> <span class="o">*</span> <span class="n">secondlargest_mask</span><span class="p">)</span><span class="o">.</span><span class="n">cpu</span><span class="p">()</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span><span class="o">.</span><span class="n">numpy</span><span class="p">())</span>

        <span class="n">is_adv_loss</span> <span class="o">=</span> <span class="n">logits</span><span class="p">[</span><span class="mi">0</span><span class="p">][</span><span class="n">secondlargest</span><span class="p">]</span> <span class="o">-</span> <span class="n">logits</span><span class="p">[</span><span class="mi">0</span><span class="p">][</span><span class="n">target</span><span class="p">]</span>

        <span class="c1"># is_adv is True as soon as the is_adv_loss goes below 0</span>
        <span class="c1"># but sometimes we want additional confidence</span>
        <span class="n">is_adv_loss</span> <span class="o">+=</span> <span class="n">confidence</span>

        <span class="k">if</span> <span class="n">is_adv_loss</span> <span class="o">==</span> <span class="mi">0</span><span class="p">:</span>
            <span class="n">is_adv_loss_grad</span> <span class="o">=</span> <span class="mi">0</span>
        <span class="k">else</span><span class="p">:</span>
            <span class="n">is_adv_loss</span><span class="o">.</span><span class="n">backward</span><span class="p">()</span>
            <span class="n">is_adv_loss_grad</span> <span class="o">=</span> <span class="n">x_p</span><span class="o">.</span><span class="n">grad</span>

        <span class="n">is_adv_loss</span> <span class="o">=</span> <span class="nb">max</span><span class="p">(</span><span class="mi">0</span><span class="p">,</span> <span class="n">is_adv_loss</span><span class="p">)</span>

        <span class="n">s</span> <span class="o">=</span> <span class="n">max_</span> <span class="o">-</span> <span class="n">min_</span>
        <span class="n">squared_l2_distance</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">sum</span><span class="p">(</span> <span class="p">((</span><span class="n">x_p</span> <span class="o">-</span> <span class="n">reconstructed_original</span><span class="p">)</span> <span class="o">**</span> <span class="mi">2</span><span class="p">)</span><span class="o">.</span><span class="n">cpu</span><span class="p">()</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span><span class="o">.</span><span class="n">numpy</span><span class="p">()</span> <span class="p">)</span> <span class="o">/</span> <span class="n">s</span> <span class="o">**</span> <span class="mi">2</span>
        <span class="n">total_loss</span> <span class="o">=</span> <span class="n">squared_l2_distance</span> <span class="o">+</span> <span class="n">const</span> <span class="o">*</span> <span class="n">is_adv_loss</span>


        <span class="n">squared_l2_distance_grad</span> <span class="o">=</span> <span class="p">(</span><span class="mi">2</span> <span class="o">/</span> <span class="n">s</span> <span class="o">**</span> <span class="mi">2</span><span class="p">)</span> <span class="o">*</span> <span class="p">(</span><span class="n">x_p</span> <span class="o">-</span> <span class="n">reconstructed_original</span><span class="p">)</span>

        <span class="c1">#print(is_adv_loss_grad)</span>
        <span class="n">total_loss_grad</span> <span class="o">=</span> <span class="n">squared_l2_distance_grad</span> <span class="o">+</span> <span class="n">const</span> <span class="o">*</span> <span class="n">is_adv_loss_grad</span>
        <span class="k">return</span> <span class="n">total_loss</span><span class="p">,</span> <span class="n">total_loss_grad</span></div>

<div class="viewcode-block" id="CarliniWagner.pending_f"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner.pending_f">[docs]</a>    <span class="k">def</span> <span class="nf">pending_f</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">x_p</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;Pending is the loss function is less than 0</span>
<span class="sd">        &quot;&quot;&quot;</span>
        <span class="n">targetlabel_mask</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">onehot_like</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">classnum</span><span class="p">),</span> <span class="bp">self</span><span class="o">.</span><span class="n">target</span><span class="p">))</span>
        <span class="n">secondlargest_mask</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">from_numpy</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">ones</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">classnum</span><span class="p">))</span> <span class="o">-</span> <span class="n">targetlabel_mask</span>
        <span class="n">targetlabel_mask</span> <span class="o">=</span> <span class="n">targetlabel_mask</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
        <span class="n">secondlargest_mask</span> <span class="o">=</span> <span class="n">secondlargest_mask</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>

        <span class="n">Zx_i</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">max</span><span class="p">((</span><span class="bp">self</span><span class="o">.</span><span class="n">model</span><span class="o">.</span><span class="n">get_logits</span><span class="p">(</span><span class="n">x_p</span><span class="p">)</span><span class="o">.</span><span class="n">double</span><span class="p">()</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span> <span class="o">*</span> <span class="n">secondlargest_mask</span><span class="p">)</span><span class="o">.</span><span class="n">cpu</span><span class="p">()</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span><span class="o">.</span><span class="n">numpy</span><span class="p">())</span>
        <span class="n">Zx_t</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">max</span><span class="p">((</span><span class="bp">self</span><span class="o">.</span><span class="n">model</span><span class="o">.</span><span class="n">get_logits</span><span class="p">(</span><span class="n">x_p</span><span class="p">)</span><span class="o">.</span><span class="n">double</span><span class="p">()</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span> <span class="o">*</span> <span class="n">targetlabel_mask</span><span class="p">)</span><span class="o">.</span><span class="n">cpu</span><span class="p">()</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span><span class="o">.</span><span class="n">numpy</span><span class="p">())</span>

        <span class="k">if</span> <span class="p">(</span> <span class="n">Zx_i</span> <span class="o">-</span> <span class="n">Zx_t</span>  <span class="o">&lt;</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">confidence</span><span class="p">):</span>
            <span class="k">return</span> <span class="kc">True</span>
        <span class="k">else</span><span class="p">:</span>
            <span class="k">return</span> <span class="kc">False</span></div>

    <span class="k">def</span> <span class="nf">to_attack_space</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">x</span><span class="p">):</span>
        <span class="n">x</span> <span class="o">=</span> <span class="n">x</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
        <span class="c1"># map from [min_, max_] to [-1, +1]</span>
        <span class="c1"># x&#39;=(x- 0.5 * (max+min) / 0.5 * (max-min))</span>
        <span class="n">a</span> <span class="o">=</span> <span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span><span class="p">)</span> <span class="o">/</span> <span class="mi">2</span>
        <span class="n">b</span> <span class="o">=</span> <span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span><span class="p">)</span> <span class="o">/</span> <span class="mi">2</span>
        <span class="n">x</span> <span class="o">=</span> <span class="p">(</span><span class="n">x</span> <span class="o">-</span> <span class="n">a</span><span class="p">)</span> <span class="o">/</span> <span class="n">b</span>

        <span class="c1"># from [-1, +1] to approx. (-1, +1)</span>
        <span class="n">x</span> <span class="o">=</span> <span class="n">x</span> <span class="o">*</span> <span class="mf">0.999999</span>

        <span class="c1"># from (-1, +1) to (-inf, +inf)</span>
        <span class="k">return</span> <span class="n">np</span><span class="o">.</span><span class="n">arctanh</span><span class="p">(</span><span class="n">x</span><span class="p">)</span>

<div class="viewcode-block" id="CarliniWagner.to_model_space"><a class="viewcode-back" href="../../../../source/deeprobust.image.attack.html#deeprobust.image.attack.cw.CarliniWagner.to_model_space">[docs]</a>    <span class="k">def</span> <span class="nf">to_model_space</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">x</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;Transforms an input from the attack space</span>
<span class="sd">        to the model space. This transformation and</span>
<span class="sd">        the returned gradient are elementwise.&quot;&quot;&quot;</span>

        <span class="c1"># from (-inf, +inf) to (-1, +1)</span>
        <span class="n">x</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">tanh</span><span class="p">(</span><span class="n">x</span><span class="p">)</span>

        <span class="n">grad</span> <span class="o">=</span> <span class="mi">1</span> <span class="o">-</span> <span class="n">np</span><span class="o">.</span><span class="n">square</span><span class="p">(</span><span class="n">x</span><span class="p">)</span>

        <span class="c1"># map from (-1, +1) to (min_, max_)</span>
        <span class="n">a</span> <span class="o">=</span> <span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span><span class="p">)</span> <span class="o">/</span> <span class="mi">2</span>
        <span class="n">b</span> <span class="o">=</span> <span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">clip_max</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">clip_min</span><span class="p">)</span> <span class="o">/</span> <span class="mi">2</span>
        <span class="n">x</span> <span class="o">=</span> <span class="n">x</span> <span class="o">*</span> <span class="n">b</span> <span class="o">+</span> <span class="n">a</span>

        <span class="n">grad</span> <span class="o">=</span> <span class="n">grad</span> <span class="o">*</span> <span class="n">b</span>
        <span class="k">return</span> <span class="n">x</span><span class="p">,</span> <span class="n">grad</span></div></div>



</pre></div>

           </div>
           
          </div>
          <footer>
  

  <hr/>

  <div role="contentinfo">
    <p>
        
        &copy; Copyright 

    </p>
  </div>
    
    
    
    Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a
    
    <a href="https://github.com/rtfd/sphinx_rtd_theme">theme</a>
    
    provided by <a href="https://readthedocs.org">Read the Docs</a>. 

</footer>

        </div>
      </div>

    </section>

  </div>
  

  <script type="text/javascript">
      jQuery(function () {
          SphinxRtdTheme.Navigation.enable(true);
      });
  </script>

  
  
    
   

</body>
</html>