| # Defended Model Artifacts - Book 3 |
|
|
| Companion artifacts for *The Applied AI Universe: Adversarial Defenses*. Book 1 |
| published the models and Book 2 the attacked ones; these are the **hardened** |
| versions, with the undefended baselines needed to reproduce each comparison. |
|
|
| | Artifact | Victim | Defense applied | Digest shipped | |
| |---|---|---|---| |
| | `capsnet.weights.h5` | Capsule network | undefended baseline | - | |
| | `capsnet_defended.weights.h5` | Capsule network | Batched adversarial training through routing | - | |
| | `cnn_mnist_defended.weights.h5` | CNN on MNIST | PGD adversarial training | - | |
| | `dnn_cifar_defended.weights.h5` | DNN on CIFAR-10 | PGD adversarial training | - | |
| | `gan_discriminator.weights.h5` | GAN discriminator | undefended baseline | - | |
| | `gan_discriminator_defended.weights.h5` | GAN discriminator | DP-SGD (per-example clipping + noise) | - | |
| | `hybrid_qnn.npz` | Hybrid quantum-classical NN | Adversarial training | yes | |
| | `mamba.weights.h5` | Selective state-space (Mamba) | undefended baseline | - | |
| | `mamba_defended.weights.h5` | Selective state-space (Mamba) | Curriculum adversarial training | - | |
| | `mlp_mnist_defended.weights.h5` | MLP on MNIST | PGD adversarial training | - | |
| | `qaoa_maxcut.npz` | QAOA MaxCut, 4-cycle | SHA-256 parameter integrity + checkpoint recovery | yes | |
| | `qgan_generator.npz` | Quantum GAN generator | SHA-256 parameter integrity + checkpoint recovery | yes | |
| | `qsvm_kernel.npz` | Quantum-kernel SVM | Distance-based anomaly rejection (demonstrably weak) | yes | |
| | `transfer_cifar.weights.h5` | MobileNetV2 transfer | undefended baseline | - | |
| | `transfer_cifar_defended.weights.h5` | MobileNetV2 transfer | Adv. training on the head; backbone frozen | - | |
| | `vqc_iris.npz` | Variational quantum classifier | PGD adversarial training | yes | |
| | `vqe_ising.npz` | VQE, transverse-field Ising | SHA-256 parameter integrity + energy cross-check | yes | |
|
|
| ## Verifying what you downloaded |
|
|
| ```python |
| import hashlib |
| d = hashlib.sha256(open('models/qaoa_maxcut.npz','rb').read()).hexdigest() |
| assert d == open('models/qaoa_maxcut.sha256').read().strip() |
| ``` |
|
|
| The same control Chapters 29, 34 and 35 apply to their own parameters. A digest |
| proves the file is unaltered since publication, **not** that what was published |
| was clean. For a variational circuit the parameters *are* the model. |
|
|
| ## Scope |
|
|
| These weights reproduce the book's **measured** results. Across 29 defenses, |
| **71% of the naive gain survived an adaptive attacker and 29% did not** - |
| integrity controls retained 100%, detection defenses 24-28%. A defense that |
| improved a naive figure may still fail an adaptive attack; the book reports both. |
|
|