VGG-face数据集通用对抗模板全NaN问题技术求助
Hey Shashank, sorry to hear you're stuck on this NaN problem with your face classification adversarial attack project—let's walk through some targeted fixes based on common pitfalls when adapting this codebase from ImageNet to VGG-Face:
Fix Input Normalization Mismatch
The original code is tuned for ImageNet's normalization rules (mean values [103.939, 116.779, 123.68]), but VGG-Face uses its own standard preprocessing (mean [129.1863, 104.7624, 93.5940]). If your face images aren't normalized correctly for VGG-Face, the model's output scores (ff(idx)) can become numerically unstable, causingproject_boundary_polyhedronto fail and return 0.- Action: Replace all ImageNet-specific preprocessing code with VGG-Face's required normalization steps. Double-check that your input tensors match the model's expected range.
Debug
ff(idx)andddfValues
A return value of 0 fromproject_boundary_polyhedronusually means it can't find a valid projection direction. This often happens if:ff(idx)(the score of the target class) is almost identical to other class scores, making the classification boundary undefined.ddf(the gradient of the loss w.r.t. input) is all zeros, which breaks the projection calculation.- Action: Add debug prints right before calling the function to check the actual values of
ff(idx)and the mean/variance ofddf. Ifddfis all zeros, ensure your VGG-Face model isn't fully frozen—you need gradients to flow for DeepFool to work.
Tweak the Polyhedron Projection Parameter
Q
TheQparameter in the original code is set for ImageNet's 1000-class distribution. VGG-Face has 2622 classes, with different class spacing and classification difficulty, so the originalQmight be too restrictive to find a valid projection.- Action: Try increasing
Qby 10-20% (start small to avoid over-perturbing) or calculate a newQbased on VGG-Face's typical class score differences.Qdefines the slack for the classification boundary, so it needs to fit your target dataset.
- Action: Try increasing
Prevent Numerical Overflow/Underflow
Even if you switched image data types, intermediate calculations inproject_boundary_polyhedronmight suffer from float32 precision loss, leading to NaNs. Division by tiny values (near zero) is another common culprit.- Action: Switch all relevant calculations to float64 to boost precision. Add a small epsilon (like
1e-8) to any denominator terms in the projection function to avoid division by zero.
- Action: Switch all relevant calculations to float64 to boost precision. Add a small epsilon (like
Ensure Model-DeepFool Compatibility
The original DeepFool implementation is built for the author's ImageNet model. VGG-Face has a different final fully connected layer dimension, which might cause shape mismatches betweenddfand the input expected byproject_boundary_polyhedron. Also, make sure your model outputs logits, not softmax probabilities—softmax can flatten gradients and cause numerical issues.- Action: Verify that
ddfhas the correct shape matching the model's output. If you're using a pre-trained VGG-Face model, confirm it's set to output raw logits instead of normalized probabilities.
- Action: Verify that
内容的提问来源于stack exchange,提问作者shawshark

