Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Adversarial Observation

A framework for black-box adversarial poisoning attacks using Particle Swarm Optimization (PSO), with analysis of attack resilience across model architectures and adversarial training regimes.

The current manuscript (in preparation) evaluates PSO-based poisoning attacks against models trained on MNIST, CIFAR-10, and AudioMNIST, examining how adversarial training (FGSM, PGD) and architecture choice (CNN, MobileNet, RegNetX) affect resilience, and whether poisoning transfers across model families.


Table of Contents

  1. Overview
  2. Requirements
  3. Setup and Installation
  4. Singularity Container
  5. Testing
  6. Package Structure
  7. Experimental Design
  8. Pipeline
  9. Directory Structure
  10. Documentation
  11. Contributing
  12. Citing This Work
  13. License

Overview

Adversarial Observation provides a PSO-based black-box adversarial attack framework built on PyTorch. The swarm optimizer searches the input space to find minimal perturbations that cause a target model to misclassify an input as a chosen false label, without requiring gradient access.

The Poison26 experiments systematically measure:

  • Resilience — how adversarial training strategies (standard, FGSM, PGD) affect susceptibility to PSO-based poisoning
  • Transfer — whether poisoning attacks that succeed against one architecture generalize to others trained on the same data

Requirements

  • Python 3.10+
  • PyTorch 2.4.1 / torchvision 0.19.1 / torchaudio 2.4.1
  • numpy, scipy, matplotlib, scikit-learn, pandas, imageio, librosa
  • captum

For HPC / reproducible runs, use the provided Singularity container (see below). For local development:

pip install -r requirements.txt

Setup and Installation

git clone https://github.com/EpiGenomicsCode/Adversarial_Observation.git
cd Adversarial_Observation
pip install -e .

Singularity Container

A Singularity definition file is provided at singularity/apso_poison.def. It builds a pytorch-captum conda environment and installs the Adversarial_Observation package into it.

Build

Run from the repository root — the %files directive copies setup.py and the Adversarial_Observation/ package relative to the current directory:

singularity build apso_poison.sif singularity/apso_poison.def

Run

Pass any command as arguments — the container executes it inside the pytorch-captum environment:

singularity exec apso_poison.sif python manuscripts/Poison26/bin/train/MNIST/train_MNIST.py \
--arch basic --training standard --output mnist_basic_standard.pt

The SLURM runbooks in manuscripts/Poison26/ reference the container via $SIF and are ready to submit directly to an A100 GPU partition.


Testing

Unit tests cover the PSO optimizer, individual particles, adversarial attacks, and data loading. All tests require PyTorch; run them inside the Singularity container or any environment where the package is installed.

Inside the container:

singularity exec apso_poison.sif python -m pytest tests/ -v

In a local conda/venv environment:

pip install -e .
pytest tests/ -v

The test_apso_singularity.py suite specifically validates the APSO workflow as used by the Poison26 attack scripts (initialization, step invariants, position clamping, and captum availability). The captum test is automatically skipped if captum is not installed in the local environment.


Package Structure

The Adversarial_Observation package:

ModulePurpose
Swarm.pyPSO orchestration — runs particles across iterations, tracks global best
BirdParticle.pyIndividual particle: position, velocity, personal best
Attacks.pyFGSM, gradient ascent, gradient maps, saliency maps
utils.pyData loading, model loading, metrics, seed utilities
visualize.pyGIF generation from per-iteration attack frames

Experimental Design

DatasetArchitecturesTraining Regimes
MNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
CIFAR-10basic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)
AudioMNISTbasic CNN, adv CNN, MobileNet, RegNetXstandard, FGSM, PGD (± augmentation)

Each model variant is trained, then subjected to PSO-based poisoning attacks targeting each possible misclassification label. Results are aggregated to produce per-model resilience scores and cross-model transfer statistics.


Pipeline

All steps are SLURM-ready scripts under manuscripts/Poison26/. Set $SIF to your built apso_poison.sif path before running.

Step 0 — Train Models

sbatch manuscripts/Poison26/00_train_models.sh

Trains all architecture × training-regime combinations for MNIST, CIFAR-10, and AudioMNIST. Model weights are saved to models/{MNIST,CIFAR10,AUDIOMNIST}/.

Step 1 — Generate Attack Labels

sbatch manuscripts/Poison26/01_generate_attack_labels.sh

Exports true labels for each dataset's test split and generates false-label targets (labels/*_labels-misclassify.tsv) used as PSO attack objectives.

Steps 2–4 — Run PSO Attacks

sbatch manuscripts/Poison26/02_attack_MNIST_Models-Resilience.sh
sbatch manuscripts/Poison26/03_attack_CIFAR10_Models-Resilience.sh
sbatch manuscripts/Poison26/04_attack_audioMNIST_Models-Resilience.sh

For each dataset, runs bin/attack/poison_<dataset>.py against every trained model variant, saving per-sample attack results (best perturbation, confidence trajectory, outcome) to TSV files.

Steps 5–6 — Aggregate Results

sbatch manuscripts/Poison26/05_calculate_FirstPass_Stats.sh
sbatch manuscripts/Poison26/06_calculate_model_Scores.sh

Computes first-iteration success rates and aggregate resilience scores. Visualization scripts in bin/chart/ generate violin and bar plots for cross-model and cross-label comparisons.


Directory Structure

Adversarial_Observation/ # installable Python package
singularity/
└── apso_poison.def # Singularity container definition (build from repo root)
manuscripts/
├── PEARC24/ # companion code for the published PEARC'24 paper
└── Poison26/ # current manuscript experiments
├── bin/
│ ├── attack/ # PSO poisoning scripts (MNIST, CIFAR10, AudioMNIST)
│ ├── chart/ # violin and bar chart generators
│ ├── eval/ # attack success evaluation
│ ├── infer/ # result aggregation / CSV merging
│ ├── train/ # model training scripts by dataset and architecture
│ └── utils/ # label export and model evaluation utilities
├── labels/ # generated true/false label TSV files
├── models/ # trained model checkpoints (not committed)
├── 00_train_models.sh
├── 01_generate_attack_labels.sh
├── 02_attack_MNIST_Models-Resilience.sh
├── 03_attack_CIFAR10_Models-Resilience.sh
├── 04_attack_audioMNIST_Models-Resilience.sh
├── 05_calculate_FirstPass_Stats.sh
└── 06_calculate_model_Scores.sh
tests/ # unit tests for PSO, particle, attacks, data loading
docs/ # Sphinx API documentation source

Documentation

Full API documentation: https://epigenomicscode.github.io/Adversarial_Observation/


Contributing

Pull requests are welcome. Please:

  • Write clear commit messages
  • Add or update tests as needed
  • Follow existing code style and conventions

Citing This Work

If you use this code, please cite the published PEARC'24 paper:

@incollection{gafur2024adversarial,
title={Adversarial Robustness and Explainability of Machine Learning Models},
author={Gafur, Jamil and Goddard, Steve and Lai, William},
booktitle={Practice and Experience in Advanced Research Computing 2024: Human Powered Computing},
pages={1--7},
year={2024}
}

A manuscript describing the Poison26 experiments is currently in preparation.


License

This project is licensed under the MIT License. See LICENSE.txt for details.

Releases

Packages

Used by

Contributors

Languages