Image Classification
Transformers
Safetensors
nula
computer-vision
cnn
cifar10
adversarial-robustness
stress-test
downsampling
anti-aliasing
custom_code
Instructions to use MamaPearl/nula-cifar10-robust-v0 with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use MamaPearl/nula-cifar10-robust-v0 with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("image-classification", model="MamaPearl/nula-cifar10-robust-v0", trust_remote_code=True) pipe("https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/parrots.png")# Load model directly from transformers import AutoModelForImageClassification model = AutoModelForImageClassification.from_pretrained("MamaPearl/nula-cifar10-robust-v0", trust_remote_code=True, device_map="auto") - Notebooks
- Google Colab
- Kaggle
Update README.md
Browse files
README.md
CHANGED
|
@@ -17,9 +17,9 @@ metrics:
|
|
| 17 |
|
| 18 |
## NULA
|
| 19 |
|
| 20 |
-
NULA
|
| 21 |
|
| 22 |
-
|
| 23 |
|
| 24 |
NULA is trained to reduce this dependence and instead form representations that remain stable under information-destroying transformations such as resizing, decimations, and aliasing-style perturbation.
|
| 25 |
|
|
@@ -28,7 +28,7 @@ NULA is trained to reduce this dependence and instead form representations that
|
|
| 28 |
|
| 29 |
Downsampling operations are linear maps from a high-dimensional space to a lower-dimensional one.
|
| 30 |
|
| 31 |
-
By the Rank-Nullity theorem, this matrix has a massive NULL space.
|
| 32 |
|
| 33 |
An attacker can exploit this: they utilize the discarded samples of these downsampling operations as extra degrees of freedom.
|
| 34 |
|
|
@@ -36,20 +36,14 @@ By sculpting perturbations with components in the null space of the downsampling
|
|
| 36 |
|
| 37 |
The result is an image perceptually identical to the original, with a manipulated activation pattern.
|
| 38 |
|
| 39 |
-
```python
|
| 40 |
-
|
| 41 |
-
```
|
| 42 |
## Approach
|
| 43 |
|
| 44 |
[BlurPool: what it does mechanically and why it addresses the problem]
|
| 45 |
[SE blocks: what they add]
|
|
|
|
|
|
|
| 46 |
|
| 47 |
|
| 48 |
-
## Architecture
|
| 49 |
-
|
| 50 |
-
[stem → s1 → s2 → s3 → head, with channel dims]
|
| 51 |
-
[BlurPool replaces strided conv — note this explicitly]
|
| 52 |
-
|
| 53 |
### FIRST EVALUATION (Base)
|
| 54 |
|
| 55 |
The first evaluation was trained for clean classification performance without the robust training procedure described above.
|
|
|
|
| 17 |
|
| 18 |
## NULA
|
| 19 |
|
| 20 |
+
NULA, an anti-aliased residual convolutional neural network for CIFAR-10 image classification, trained to be robust against perturbations that exploit downsampling operations.
|
| 21 |
|
| 22 |
+
Classical image models rely on fragile high-frequency cues, which downsampling operators destroy or alias exactly to those components.
|
| 23 |
|
| 24 |
NULA is trained to reduce this dependence and instead form representations that remain stable under information-destroying transformations such as resizing, decimations, and aliasing-style perturbation.
|
| 25 |
|
|
|
|
| 28 |
|
| 29 |
Downsampling operations are linear maps from a high-dimensional space to a lower-dimensional one.
|
| 30 |
|
| 31 |
+
By the Rank-Nullity theorem, this matrix has a massive NULL space ;).
|
| 32 |
|
| 33 |
An attacker can exploit this: they utilize the discarded samples of these downsampling operations as extra degrees of freedom.
|
| 34 |
|
|
|
|
| 36 |
|
| 37 |
The result is an image perceptually identical to the original, with a manipulated activation pattern.
|
| 38 |
|
|
|
|
|
|
|
|
|
|
| 39 |
## Approach
|
| 40 |
|
| 41 |
[BlurPool: what it does mechanically and why it addresses the problem]
|
| 42 |
[SE blocks: what they add]
|
| 43 |
+
The augmentation functions used during adversarial training are in [`augmentations.py`](augmentations.py).
|
| 44 |
+
The training script is [`train_robust.py`](train_robust.py).
|
| 45 |
|
| 46 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 47 |
### FIRST EVALUATION (Base)
|
| 48 |
|
| 49 |
The first evaluation was trained for clean classification performance without the robust training procedure described above.
|