FSAA allows to create adversarial examples that corrupt the features of the victim models. Various attacks are possible, by altering initialization and update strategies, losses and perceptual masks. FSAA is written in Python and is based on PyTorch.
If you would like to use fsaa in you project, simply run:
pip install fsaaimport requests as r
from PIL import Image
import torch
from torchvision.transforms import ToTensor
from fsaa import attack
from fsaa.models import get_default_transform, get_model
# Getting device
device = torch.device("cuda" if torch.cuda.is_available() else "cpu")
# Getting model and transform
name = "facebook/dinov2-large"
model = get_model(name).to(device).eval()
transform = get_default_transform(name)
# Getting data
url = "http://images.cocodataset.org/val2017/000000039769.jpg"
image = Image.open(r.get(url, stream=True).raw).convert("RGB").resize((224, 224))
batch = ToTensor()(image).unsqueeze(0).to(device)
# Computing attack
adv_batch = attack(
model,
batch,
transform,
steps=350,
max_img_mse=1e-4,
pbar=True,
scheduler_fn=torch.optim.lr_scheduler.CosineAnnealingLR,
scheduler_kwargs={"T_max": 350},
do_flatten_features=True,
)
with torch.no_grad():
y1 = model(transform(batch))
y2 = model(transform(adv_batch))
cossim = torch.nn.functional.cosine_similarity(y1.flatten(1), y2.flatten(1), dim=-1)
print(f"Cosine Similarity: {cossim.item():.4f}")Please refer to the tutorial notebook for a more detailed explanation.
Contributions are highly welcome! Please refer to the contributing guidelines.
The code is distributed according to the Attribution-NonCommercial 4.0 International LICENSE.
If you used this library as part of your work, please cite the repository as follows:
@software{Pulfer_FSAA_2024,
author = {Pulfer, Brian},
month = April
title = {{FSAA}},
url = {https://github.com/BrianPulfer/fsaa},
version = {0.0.2},
year = {2024}
}