diff options
author | Jan Aalmoes <jan.aalmoes@inria.fr> | 2024-09-21 16:33:51 +0200 |
---|---|---|
committer | Jan Aalmoes <jan.aalmoes@inria.fr> | 2024-09-21 16:33:51 +0200 |
commit | b8504c330be30ccf771d6745a34f395a83395ea5 (patch) | |
tree | 9bbd9285d530381e3e743266fbf62be35df3a7c8 /ACSAC/figures/fig_advdebias_attacc.tex | |
parent | 00ec61946ddf3a7c2abf7d7e0730fc8e21b50f37 (diff) | |
parent | 06c724f61e746772dc46aaf7e11c96abc1a49dd1 (diff) |
merge with brouillon
Diffstat (limited to 'ACSAC/figures/fig_advdebias_attacc.tex')
-rw-r--r-- | ACSAC/figures/fig_advdebias_attacc.tex | 139 |
1 files changed, 139 insertions, 0 deletions
diff --git a/ACSAC/figures/fig_advdebias_attacc.tex b/ACSAC/figures/fig_advdebias_attacc.tex new file mode 100644 index 0000000..6c4d29a --- /dev/null +++ b/ACSAC/figures/fig_advdebias_attacc.tex @@ -0,0 +1,139 @@ +% \begin{figure}[!htb] +% \centering +% \begin{minipage}[b]{\linewidth} +% \centering +% \subfigure[\census (\race)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf} +% }% +% \subfigure[\census (\sex)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf} +% } +% \end{minipage}% + + +% \begin{minipage}[b]{\linewidth} +% \centering +% \subfigure[\compas (\race)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf} +% }% +% \subfigure[\compas (\sex)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf} +% } +% \end{minipage}% + +% \begin{minipage}[b]{\linewidth} +% \centering +% \subfigure[\meps (\race)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf} +% }% +% \subfigure[\meps (\sex)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf} +% } +% \end{minipage}% + +% \begin{minipage}[b]{\linewidth} +% \centering +% \subfigure[\lfw (\race)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf} +% }% +% \subfigure[\lfw (\sex)]{ +% \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf} +% } +% \end{minipage}% + +% \caption{%For both \adaptiveAIASoft and \adaptiveAIAHard, w +% We observe that \advdebias reduces the attack accuracy to random guess ($\sim$50\%). %Additionally for \adaptiveAIAHard, the theoretical bound on attack accuracy (``Theory'') matches with the empirical results (``Empirical''). +% } +% \label{fig:AdaptAIADebias} +% \end{figure} + + + + + +\begin{figure*}[!htb] + \centering + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIASoft: \census (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf} + }% + \subfigure[\adaptiveAIASoft: \census (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf} + } + \end{minipage}% + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIAHard: \census (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf} + }% + \subfigure[\adaptiveAIAHard: \census (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf} + } + \end{minipage}\\ + + + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIASoft: \compas (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf} + }% + \subfigure[\adaptiveAIASoft: \compas (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf} + } + \end{minipage}% + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIAHard: \compas (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf} + }% + \subfigure[\adaptiveAIAHard: \compas (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf} + } + \end{minipage}\\ + + + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIASoft: \meps (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf} + }% + \subfigure[\adaptiveAIASoft: \meps (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf} + } + \end{minipage}% + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIAHard: \meps (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf} + }% + \subfigure[\adaptiveAIAHard: \meps (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf} + } + \end{minipage}\\ + + + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIASoft: \lfw (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf} + }% + \subfigure[\adaptiveAIASoft: \lfw (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf} + } + \end{minipage}% + \begin{minipage}[b]{0.49\linewidth} + \centering + \subfigure[\adaptiveAIAHard: \lfw (\race)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf} + }% + \subfigure[\adaptiveAIAHard: \lfw (\sex)]{ + \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf} + } + \end{minipage} + +\vspace{-2mm} + \caption{For both \adaptiveAIASoft and \adaptiveAIAHard, \advdebias reduces the attack accuracy to random guess ($\sim$50\%). For \adaptiveAIAHard, the theoretical bound on attack accuracy (\theoretical) matches with the empirical results (\empirical).} + \label{fig:AdaptAIADebias} + \vspace{-2mm} +\end{figure*} |