Spaces:
Running
Running
equation
Browse files- index.html +3 -2
index.html
CHANGED
|
@@ -421,7 +421,7 @@
|
|
| 421 |
<p>
|
| 422 |
Attackers can design adaptive attacks to try to bypass BEYOND when the attacker knows all the parameters of the model
|
| 423 |
and the detection strategy. For an SSL model with a feature extractor <i>f</i>, a projector <i>h</i>, and a classification head <i>g</i>,
|
| 424 |
-
the classification branch can be formulated as <strong>C</strong>= <i>f</i> ° <i>g</i> and the representation branch as <strong>R</strong> = <i>f</i> ° <i>h</i>.
|
| 425 |
To attack effectively, the adversary must deceive the target model while guaranteeing the label consistency and representation similarity of the SSL model.
|
| 426 |
</div>
|
| 427 |
</div>
|
|
@@ -466,7 +466,8 @@
|
|
| 466 |
</p>
|
| 467 |
|
| 468 |
<p class="formula total-loss formula-content" style="display: none;">
|
| 469 |
-
where <strong><i>L</i></strong><sub>C</sub> indicates classifier's loss function, <i>y</i><sub><i>t</i></sub> is the targeted class, and &alpha refers to a hyperparameter
|
|
|
|
| 470 |
</p>
|
| 471 |
</div>
|
| 472 |
</div>
|
|
|
|
| 421 |
<p>
|
| 422 |
Attackers can design adaptive attacks to try to bypass BEYOND when the attacker knows all the parameters of the model
|
| 423 |
and the detection strategy. For an SSL model with a feature extractor <i>f</i>, a projector <i>h</i>, and a classification head <i>g</i>,
|
| 424 |
+
the classification branch can be formulated as <strong>C</strong>= <i>f</i> ° <i>g</i> and the representation branch as <strong>R</strong> = <i>f</i> ° <i>h</i>.
|
| 425 |
To attack effectively, the adversary must deceive the target model while guaranteeing the label consistency and representation similarity of the SSL model.
|
| 426 |
</div>
|
| 427 |
</div>
|
|
|
|
| 466 |
</p>
|
| 467 |
|
| 468 |
<p class="formula total-loss formula-content" style="display: none;">
|
| 469 |
+
where <strong><i>L</i></strong><sub>C</sub> indicates classifier's loss function, <i>y</i><sub><i>t</i></sub> is the targeted class, and α refers to a hyperparameter,
|
| 470 |
+
which is a trade-off parameter between label consistency and representation similarity..
|
| 471 |
</p>
|
| 472 |
</div>
|
| 473 |
</div>
|