Downloads · 30 days
0
KaiwenDu/robust-overfitting-checkpoints
robust-overfitting-checkpoints is a image classification model from KaiwenDu. Use it when you need a label for an image. It is set up for pytorch. The card lists the license as mit.
This repository contains PyTorch model checkpoints from our study investigating robust overfitting in PreActResNet-18 on CIFAR-10 across three multi-seed adversarial-training conditions: pixel-space PGD, low-frequency…
Downloads · 30 days
0
Access
Public
Updated Sep 8, 2026
Repo size
111 GB
Likes
0
Public
Click a slice to open those files.
.pt53.7 GB · 100%
From the Hugging Face model README
This repository contains PyTorch model checkpoints from our study investigating robust overfitting in PreActResNet-18 on CIFAR-10 across three multi-seed adversarial-training conditions: pixel-space PGD, low-frequency DCT-masked PGD, and mixed-domain training.
The checkpoints are intended for research, reproduction, and analysis of how clean and adversarial robustness change throughout training.
KaiwenDu/robust-overfitting-checkpoints/
├── pixel-only/ # Pixel-space PGD-10 multi-seed runs (40 checkpoints each)
│ ├── seed-42/
│ ├── seed-43/
│ ├── seed-44/
│ ├── seed-45/
│ └── seed-46/
├── low-frequency-only/ # Low-frequency DCT-masked PGD-10 (Cutoff = 8, 40 checkpoints each)
│ ├── seed-42/
│ ├── seed-43/
│ ├── seed-44/
│ ├── seed-45/
│ └── seed-46/
└── mixed-domain/ # Mixed pixel/DCT PGD-10 multi-seed runs (40 checkpoints each)
├── seed-42/
├── seed-43/
├── seed-44/
├── seed-45/
└── seed-46/
pixel-only/seed-<seed>/)low-frequency-only/seed-<seed>/)mixed-domain/seed-<seed>/)epoch_5.pt through epoch_200.pt)The model architecture and full training code are available in the companion GitHub repository:
https://github.com/ItsKaiwenDu/Robust-Overfitting
Each checkpoint was evaluated on the full CIFAR-10 test set using 20-step PGD (both standard pixel-space PGD and DCT-masked low-frequency PGD with cutoff $k=8$) with epsilon = 8/255 and step size = 2/255. Joint robustness measures the percentage of test samples classified correctly under both evaluated attack types.
| Evaluation Condition / Checkpoint | Clean accuracy | Pixel-PGD-20 robust accuracy | Low-Freq PGD-20 robust accuracy | Joint robustness |
|---|---|---|---|---|
| Pixel-Only Multi-Seed (Seeds 42–46 Mean ± SD) | ||||
| Epoch 105 (best pixel robustness) | 83.04% ± 0.33% | 51.22% ± 0.28% | 77.70% ± 0.27% | 51.22% ± 0.28% |
| Epoch 200 (final checkpoint) | 84.40% ± 0.09% | 42.66% ± 0.22% | 76.48% ± 0.26% | 42.66% ± 0.22% |
| Low-Frequency-Only Multi-Seed (Seeds 42–46 Mean ± SD) | ||||
| Epoch 195 (best low-frequency robustness) | 94.24% ± 0.19% | 0.00% ± 0.00% | 92.74% ± 0.17% | 0.00% ± 0.00% |
| Epoch 200 (final checkpoint) | 94.28% ± 0.22% | 0.00% ± 0.00% | 92.70% ± 0.28% | 0.00% ± 0.00% |
| Mixed-Domain Multi-Seed (Seeds 42–46 Mean ± SD) | ||||
| Epoch 85 (best pixel & joint robustness) | 71.86% ± 0.88% | 40.80% ± 0.78% | 66.16% ± 0.80% | 40.79% ± 0.79% |
| Epoch 200 (final checkpoint) | 90.33% ± 3.45% | 19.33% ± 14.28% | 85.20% ± 4.29% | 19.33% ± 14.27% |
epoch_105.pt for peak pixel and joint robustness, or epoch_200.pt to evaluate the final model after robust overfitting.epoch_195.pt for the highest measured low-frequency robustness (92.74%), or epoch_200.pt for the highest measured clean accuracy (94.28%).epoch_85.pt records the highest aggregate pixel and joint robustness, but it follows a pixel-training epoch. The checkpoints do not provide stable simultaneous robustness to both threats.epoch_5.pt to epoch_200.pt) to reproduce and analyze clean and robust accuracy curves across training.Clone the companion code repository first, since it contains the PreActResNet-18 definition:
git clone https://github.com/ItsKaiwenDu/Robust-Overfitting.git
cd Robust-Overfitting
pip install -r requirements.txt
Then download and load a checkpoint:
import torch
from huggingface_hub import hf_hub_download
from models.preact_resnet import PreActResNet18
# Example: Download Epoch 85 from Mixed-Domain training (Seed 42)
checkpoint_path = hf_hub_download(
repo_id="KaiwenDu/robust-overfitting-checkpoints",
filename="epoch_85.pt",
subfolder="mixed-domain/seed-42",
)
# Example: Download Epoch 105 from Pixel-Only training (Seed 42)
# checkpoint_path = hf_hub_download(
# repo_id="KaiwenDu/robust-overfitting-checkpoints",
# filename="epoch_105.pt",
# subfolder="pixel-only/seed-42",
# )
# Example: Download Epoch 105 from Low-Frequency training (Seed 42)
# checkpoint_path = hf_hub_download(
# repo_id="KaiwenDu/robust-overfitting-checkpoints",
# filename="epoch_105.pt",
# subfolder="low-frequency-only/seed-42",
# )
device = torch.device("cuda" if torch.cuda.is_available() else "cpu")
model = PreActResNet18(num_classes=10).to(device)
checkpoint = torch.load(checkpoint_path, map_location=device)
model.load_state_dict(checkpoint["model_state_dict"])
model.eval()
Inputs should be CIFAR-10 RGB images converted to tensors in [0, 1] and normalized with:
mean = (0.4914, 0.4822, 0.4465)
std = (0.2471, 0.2435, 0.2616)
These checkpoints represent empirical research studies on robust overfitting, not a claim of state-of-the-art adversarial robustness. Robustness was measured against specified pixel-space and DCT-masked low-frequency PGD-20 attacks; it should not be interpreted as robustness against every possible attack.
If you use these checkpoints, please cite the companion repository and the original robust-overfitting paper:
@article{rice2020overfitting,
title={Overfitting in Adversarially Robust Deep Learning},
author={Rice, Leslie and Wong, Eric and Kolter, J. Zico},
journal={Proceedings of the 37th International Conference on Machine Learning},
year={2020}
}
The companion code is released under the MIT License. CIFAR-10 is subject to its own dataset terms and license.