Downloads · 30 days
0
Drint/cat_vs_dog
cat_vs_dog is a machine learning model from Drint. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Training : Model was trained for both classes 4000 images and trained on 1000 images, Epochs = 5. The pipeline of the project involves augmenting the images to standard tensor size of (3,224,224), and for 5 epochs to…
Downloads · 30 days
0
Access
Public
Updated Aug 22, 2024
Repo size
10.7 MB
Likes
0
Public
Click a slice to open those files.
.pth10.7 MB · 100%
From the Hugging Face model README
Training : Model was trained for both classes 4000 images and trained on 1000 images, Epochs = 5. The pipeline of the project involves augmenting the images to standard tensor size of (3,224,224), and for 5 epochs to train network independent of the oder of the images getting trained. Augmentation of image involves mirroring , shrinking , padding , rotating and padding to improve the robustness in training.
Total params: 2,668,418 Trainable params: 2,668,418
Attack: FGSM(Fast Gradient Sign Method ) Xadv = x - ϵ.sign(∇xJ(θ,x,ytarget)) x-Clean Input Image J-Lossfunction Ytarget - Target Label ϵ - Epsilon When ϵ=0 ,is image in which perturbation is not performed, whereas ϵ=1, Image is perturbed largely.
● Research Background: Fgsm attack attacks the gradient and perturbs the image ,Most of the defense techniques that deals with these attack are denoising, random padding and averaging. <br /> ● Theoretical Ananlysis: The attack is performed to check how robust is classifier , Even human can still distinguish the both class after perturbation ,but to train the model such robustness attackand defense techniques are performed. Defense mitigates by denoising the perturbations and makes feasible for classifier to distinguish. <br /> ● Implementation: Dataset I used was cat_vs_dog , network architecture is shown above. The model was trained for 4000 images and tested for 1000 images. Defense technique will be performed by augmenting the attacked image through various techniques such as random padding and denoising. <br /> ● Numerical Analysis: Attack is performed for different values of the epsilon(0 , 0.05, 0.1, 0.15, 0.2, 0.25, 0.3), and model is trained to classify the perturbed image and below is the image that model misclassifies the <br /> ● Suggested Improvements: To improve the classification, denising techniques which averages the neighbor pixels to remove noise and augment the image , and then fed back to network to improve accuracy.The model is attached to the following file as pth extension and collab notebook