| license: apache-2.0 | |
| task_categories: | |
| - image-classification | |
| tags: | |
| - adversarial-robustness | |
| - fgsm | |
| - adversarial-training | |
| - pytorch | |
| # PixelShield | |
| PixelShield stress-tests the 2,198-parameter Tiny Vision student against Fast Gradient | |
| Sign Method perturbations, then adversarially fine-tunes an architecture-identical | |
| copy. | |
| The benchmark reports clean accuracy and robust accuracy at several normalized | |
| pixel-space perturbation budgets. FGSM is a first-order white-box attack, so this | |
| project is an educational robustness baseline rather than a security guarantee. | |
| ## Reproduce | |
| ```powershell | |
| uv run python projects/tiny-vision-foundry/prepare_data.py | |
| uv run python projects/pixel-shield/train.py | |
| ``` | |
| ## Verified results | |
| | FGSM epsilon | Baseline accuracy | Adversarially trained | Change | | |
| | ---: | ---: | ---: | ---: | | |
| | 0.00 | **98.52%** | 94.44% | -4.07 points | | |
| | 0.05 | 82.96% | **89.26%** | +6.30 points | | |
| | 0.10 | 46.30% | **74.81%** | +28.52 points | | |
| | 0.15 | 20.37% | **55.56%** | +35.19 points | | |
| | 0.20 | 12.22% | **32.59%** | +20.37 points | | |
| | 0.25 | 7.04% | **14.07%** | +7.04 points | | |
| The robust model has the same 2,198 parameters as the baseline. Its clean-accuracy | |
| cost is 4.07 percentage points. Results use a white-box FGSM attack against each model | |
| separately, avoiding transfer-attack inflation. | |