-
Notifications
You must be signed in to change notification settings - Fork 17
Open
Description
Hello,
When trying to generate the adversarial dataset for the EMNIST+ARDIS setting I noticed that the honest (EMNIST) images and the ARDIS images have a different orientation. Specifically, the images from torchvision EMNIST dataset are 90 degrees rotated and mirrored (in generating_poisoned_DA.py), whereas the ARDIS-7's have a normal orientation. The images are then saved together into one attacker dataset. Therefore, it seems that you are training a model on 90deg+mirrored EMNIST while inserting an edge-case ARDIS backdoor that is not rotated/flipped.
Am I missing something here (are you correcting these EMNIST images later somewhere)?
Thanks,
Hidde
Metadata
Metadata
Assignees
Labels
No labels