File size: 15,276 Bytes
957e2dc
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
import torch
import torch.nn as nn

from typing import Tuple, Union
from torch.utils.data import Dataset, TensorDataset, DataLoader

from src.utils.writer import Writer
from src.pipelines.pipeline import Pipeline
from src.loss.adversarial import AdversarialLoss
from src.loss.auxiliary import AuxiliaryLoss

################################################################################
# Base class for offline adversarial attacks
################################################################################


class OfflineAttack:

    def __init__(self,

                 pipeline: Pipeline,

                 adv_loss: AdversarialLoss,

                 aux_loss: AuxiliaryLoss = None,

                 batch_size: int = 32,

                 rand_evals: int = 0,

                 writer: Writer = None,

                 **kwargs

                 ):
        """

        Base class for offline attacks. Subclasses must override the

        `evaluate_batch()` method.



        Offline attacks optimize perturbations of benign inputs without

        real-time performance constraints. Optimization is performed using a

        stored Pipeline object, encompassing a victim model, acoustic

        simulation, and adversarial defenses.



        :param pipeline: a Pipeline object wrapping a (defended) classifier

        :param adv_loss: AdversarialLoss object encapsulating attacker objective

        :param aux_loss: optional AuxiliaryLoss object encapsulating

                         some perceptibility objective

        :param batch_size: batch size for attack

        :param rand_evals: randomly-resampled simulated evaluations per each

                           final generated attack

        """
        self.pipeline = pipeline

        # ensure gradients flow through PyTorch RNN layers
        self._pipeline_rnn_grad()

        self.adv_loss = adv_loss
        self.aux_loss = aux_loss

        self.batch_size = batch_size
        self.rand_evals = rand_evals

        # log attack progress
        self.writer = writer

        # track batch inputs
        self._batch_id = 0
        self._iter_id = 0

        # optional data-loading arguments
        self.pin_memory = kwargs.get('pin_memory', False)
        self.num_workers = kwargs.get('num_workers', 0)

        self._check_loss()

    def _pipeline_rnn_grad(self):
        """

        PyTorch requires any recurrent modules be placed in `train` mode to

        enable backpropagation through the pipeline.

        """
        for m in self.pipeline.modules():
            if isinstance(m, nn.RNNBase):
                m.train()

    def _check_loss(self):
        """

        Validate adversarial and auxiliary losses

        """

        assert self.adv_loss is not None, 'Must provide adversarial loss'
        assert self.adv_loss.reduction in ['none', None], \
            'All losses must provide unreduced scores'

        assert self.aux_loss is None or \
               self.aux_loss.reduction in ['none', None], \
            'All losses must provide unreduced scores'

    @staticmethod
    def _create_dataset(x: torch.Tensor, y: torch.Tensor):
        """

        If attack inputs are given as tensors, create a simple dataset

        """

        # require batch dimension
        assert x.ndim >= 2

        dataset = TensorDataset(
            x.type(torch.float32),
            y.type(torch.float32),
        )
        return dataset

    def _compute_detection_array(self, x_adv, *args, **kwargs):
        """

        Pass attack audio through any detection defenses in stored Pipeline, and

        return boolean detection flags for each input

        """
        flags, scores = self.pipeline.detect(x_adv)
        return flags

    @torch.no_grad()
    def _compute_success_array(self,

                               x: torch.Tensor,

                               y: torch.Tensor,

                               x_adv: torch.Tensor,

                               *args,

                               **kwargs

                               ):
        """

        Pass attack audio through stored Pipeline and determine adversarial

        success for each input

        """

        # obtain 'clean' and adversarial predictions of stored Pipeline
        preds = self.pipeline(x.detach())
        adv_preds = self.pipeline(x_adv.detach())

        # for a targeted attack, attempt to match given targets
        if self.adv_loss.targeted:
            attack_success = self.pipeline.match_predict(adv_preds, y)

        # for an untargeted attack, attempt to evade clean predictions
        else:
            attack_success = ~self.pipeline.match_predict(adv_preds, preds)

        return attack_success

    def _log_step(self,

                  x: torch.Tensor,

                  x_adv: torch.Tensor,

                  y: torch.Tensor,

                  adv_loss: Union[float, torch.Tensor] = None,

                  det_loss: Union[float, torch.Tensor] = None,

                  aux_loss: Union[float, torch.Tensor] = None,

                  success_rate: Union[float, torch.Tensor] = None,

                  detection_rate: Union[float, torch.Tensor] = None,

                  idx: int = 0,

                  tag: str = None,

                  *args,

                  **kwargs

                  ):
        """

        Log attack progress.



        :param x: batch of original inputs

        :param x_adv: batch of adversarial inputs

        :param y: batch of adversarial targets

        :param adv_loss: adversarial loss value

        :param det_loss: detection loss value

        :param aux_loss: auxiliary loss value

        :param success_rate: adversarial success rate

        :param detection_rate: adversarial defense detection rate

        :param idx: batch index for logging individual examples

        """

        if self.writer is None or self._iter_id % self.writer.log_iter:
            return

        if tag is None:
            tag = f'{self.__class__.__name__}-batch-{self._batch_id}'

        x = x.clone().detach()
        x_adv = x_adv.clone().detach()

        # compute losses and simulated audio
        with torch.no_grad():
            outputs_adv = self.pipeline(x_adv)
            simulated = self.pipeline.simulate(x)
            simulated_adv = self.pipeline.simulate(x_adv)

            # if adversarial loss is not provided, compute
            if adv_loss is None:
                adv_loss = self.adv_loss(outputs_adv, y).mean()

            # if detector loss or rate is not provided, compute
            if det_loss is None or detection_rate is None:
                flags, scores = self.pipeline.detect(x_adv)
                det_loss = scores.mean()
                detection_rate = torch.mean(1.0 * flags)

            # if auxiliary loss is not provided, compute
            if aux_loss is None:
                aux_loss = 0.0 if self.aux_loss is None else self.aux_loss(
                    x_adv, x
                ).mean()

            # if adversarial success rate is not provided, compute
            if success_rate is None:
                success = self._compute_success_array(
                    x=x,
                    x_adv=x_adv,
                    y=y
                )
                success_rate = torch.mean(1.0 * success)

        # unperturbed input
        self.writer.log_audio(
            x[idx],
            f"{tag}/original",
            global_step=self._iter_id
        )

        # simulated unperturbed input
        self.writer.log_audio(
            simulated[idx],
            f"{tag}/simulated-original",
            global_step=self._iter_id
        )

        # adversarial input
        self.writer.log_audio(
            x_adv[idx],
            f"{tag}/adversarial",
            global_step=self._iter_id
        )

        # simulated adversarial input
        self.writer.log_audio(
            simulated_adv[idx],
            f"{tag}/simulated-adversarial",
            global_step=self._iter_id
        )

        # adversarial loss value
        self.writer.log_scalar(
            adv_loss,
            f"{tag}/adversarial-loss",
            global_step=self._iter_id
        )

        # detector loss value
        self.writer.log_scalar(
            det_loss,
            f"{tag}/detector-loss",
            global_step=self._iter_id
        )

        # auxiliary loss value
        self.writer.log_scalar(
            aux_loss,
            f"{tag}/auxiliary-loss",
            global_step=self._iter_id
        )

        # adversarial success rate
        self.writer.log_scalar(
            success_rate,
            f"{tag}/success-rate",
            global_step=self._iter_id
        )

        # adversarial detection rate
        self.writer.log_scalar(
            detection_rate,
            f"{tag}/detection-rate",
            global_step=self._iter_id
        )

    def _evaluate_batch(self,

                        x: torch.Tensor,

                        y: torch.Tensor,

                        **kwargs

                        ):
        """

        Perform attack on a batch of inputs.



        :param x: input tensor of shape (n_batch, ...)

        :param y: targets tensor of shape (n_batch, ...) in case of targeted

                  attack; original labels tensor of shape (n_batch, ...) in

                  case of untargeted attack

        """
        raise NotImplementedError()

    @torch.no_grad()
    def evaluate(self,

                 x: torch.Tensor = None,

                 y: torch.Tensor = None,

                 dataset: Dataset = None,

                 **kwargs

                 ) -> Tuple[torch.Tensor, torch.Tensor, torch.Tensor]:
        """

        Perform attack given input-target pairs, optionally in the form of a

        Dataset object. Random evaluations will then be conducted on all

        generated attacks.



        :param x: audio input, shape (n_batch, ..., signal_length)

        :param y: targets, shape (n_batch, ...)

        :param dataset: optionally, provide inputs and targets as dataset

        :return: tuple holding

                   * adversarial audio (n_batch, ..., signal_length)

                   * boolean adversarial success indicators (n_batch,)

                   * boolean adversarial detection indicators (n_batch,)

        """

        assert (x is not None and y is not None) or dataset is not None

        # prepare batched data-loading, store original device
        if dataset is None:
            orig_device = x.device
            dataset = self._create_dataset(x, y)
            x_ref = x[0:1].clone().detach()
        else:
            ref_batch = next(iter(dataset))
            if isinstance(ref_batch, tuple):
                x_ref = ref_batch[0]
            elif isinstance(ref_batch, dict):
                x_ref = ref_batch['x']
            else:
                x_ref = ref_batch
            orig_device = x_ref.device

        # prepare to compute attack success and detection rates
        attack_success = torch.zeros(
            len(dataset), dtype=torch.float).to(self.pipeline.device)
        attack_detection = torch.zeros(
            len(dataset), dtype=torch.float).to(self.pipeline.device)

        # prepare to store attack outputs
        adv_x = torch.stack(
            [torch.zeros(x_ref.shape)] * len(dataset),
            dim=0
        ).to(self.pipeline.device)

        data_loader = DataLoader(
            dataset=dataset,
            batch_size=self.batch_size,
            shuffle=False,
            drop_last=False,
            num_workers=self.num_workers,
            pin_memory=self.pin_memory
        )

        # compute attacks with batching
        for (batch_id, batch_all) in enumerate(data_loader):

            self._batch_id = batch_id

            # allow for different dataset formats
            if isinstance(batch_all, tuple):
                batch_all = {
                    'x': batch_all[0],
                    'y': batch_all[1]
                }

            # match devices
            for k in batch_all.keys():
                batch_all[k] = batch_all[k].to(self.pipeline.device)

            batch_index_1 = batch_id * self.batch_size
            batch_index_2 = (batch_id + 1) * self.batch_size

            # compute attacks for given batch
            adversarial_batch = self._evaluate_batch(
                **batch_all, **kwargs
            )

            # if no random trials, evaluate once
            if not self.rand_evals:

                # compute and store success rates for batch
                attack_success_batch = self._compute_success_array(
                    **batch_all,
                    x_adv=adversarial_batch
                ).reshape(-1).type(torch.float32)

                # compute and store detection rates for batch
                attack_detection_batch = self._compute_detection_array(
                    x_adv=adversarial_batch
                ).reshape(-1).type(torch.float32)

            # otherwise, perform multiple random evaluations per attack
            else:

                # track batch success and detection over random evaluation
                success_combined_batch = []
                detection_combined_batch = []

                for i in range(self.rand_evals):

                    # randomly sample simulation parameters
                    self.pipeline.sample_params()

                    # compute and store success rates for batch
                    rand_success_batch = self._compute_success_array(
                        **batch_all,
                        x_adv=adversarial_batch
                    ).reshape(-1, 1)
                    success_combined_batch.append(rand_success_batch)

                    # compute and store detection rates for batch
                    rand_detection_batch = self._compute_detection_array(
                        x_adv=adversarial_batch
                    )
                    detection_combined_batch.append(rand_detection_batch)

                # average results over all trials
                attack_success_batch = (1.0 * torch.cat(
                    success_combined_batch, dim=-1
                )).mean(dim=-1)

                attack_detection_batch = (1.0 * torch.cat(
                    detection_combined_batch, dim=-1
                )).mean(dim=-1)

            # store generated attack audio
            adv_x[batch_index_1:batch_index_2] = adversarial_batch

            # store success rate per generated attack
            attack_success[batch_index_1:batch_index_2] = attack_success_batch

            # store detection rate per generated attack
            attack_detection[batch_index_1:batch_index_2] = attack_detection_batch

        return (adv_x.to(orig_device),
                attack_success.to(orig_device),
                attack_detection.to(orig_device))