Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Input format of attack images #62

Open
yi-sun opened this issue Dec 1, 2018 · 1 comment
Open

Input format of attack images #62

yi-sun opened this issue Dec 1, 2018 · 1 comment

Comments

@yi-sun
Copy link

yi-sun commented Dec 1, 2018

During the contest itself, what will be the required input format of the attack images? The current images in bird-or-bicycle are 299 x 299 .jpg files.

  1. Will this be the required dimension?
  2. It may be more convenient for attackers to generate .png attacks, without changing the spirit of the contest. Will .jpg be required?
@carlini
Copy link
Collaborator

carlini commented Dec 1, 2018

I think 299x299x3 PNG would be a perfectly fine format, but I don't think we've settled on those details.

Note that I don't think PNG/JPG/GIF actually changes much for attackers -- a defense could just as well apply these compression approaches as a pre-processing function, so it seems about as easy or hard for an attacker regardless of the input format.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants