% \begin{figure}[!htb] % \centering % \begin{minipage}[b]{\linewidth} % \centering % \subfigure[\census (\race)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf} % }% % \subfigure[\census (\sex)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf} % } % \end{minipage}% % \begin{minipage}[b]{\linewidth} % \centering % \subfigure[\compas (\race)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf} % }% % \subfigure[\compas (\sex)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf} % } % \end{minipage}% % \begin{minipage}[b]{\linewidth} % \centering % \subfigure[\meps (\race)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf} % }% % \subfigure[\meps (\sex)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf} % } % \end{minipage}% % \begin{minipage}[b]{\linewidth} % \centering % \subfigure[\lfw (\race)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf} % }% % \subfigure[\lfw (\sex)]{ % \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf} % } % \end{minipage}% % \caption{%For both \adaptiveAIASoft and \adaptiveAIAHard, w % We observe that \advdebias reduces the attack accuracy to random guess ($\sim$50\%). %Additionally for \adaptiveAIAHard, the theoretical bound on attack accuracy (``Theory'') matches with the empirical results (``Empirical''). % } % \label{fig:AdaptAIADebias} % \end{figure} \begin{figure*}[!htb] \centering \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIASoft: \census (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf} }% \subfigure[\adaptiveAIASoft: \census (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf} } \end{minipage}% \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIAHard: \census (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf} }% \subfigure[\adaptiveAIAHard: \census (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf} } \end{minipage}\\ \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIASoft: \compas (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf} }% \subfigure[\adaptiveAIASoft: \compas (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf} } \end{minipage}% \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIAHard: \compas (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf} }% \subfigure[\adaptiveAIAHard: \compas (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf} } \end{minipage}\\ \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIASoft: \meps (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf} }% \subfigure[\adaptiveAIASoft: \meps (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf} } \end{minipage}% \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIAHard: \meps (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf} }% \subfigure[\adaptiveAIAHard: \meps (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf} } \end{minipage}\\ \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIASoft: \lfw (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf} }% \subfigure[\adaptiveAIASoft: \lfw (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf} } \end{minipage}% \begin{minipage}[b]{0.49\linewidth} \centering \subfigure[\adaptiveAIAHard: \lfw (\race)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf} }% \subfigure[\adaptiveAIAHard: \lfw (\sex)]{ \includegraphics[width=0.48\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf} } \end{minipage} \vspace{-2mm} \caption{For both \adaptiveAIASoft and \adaptiveAIAHard, \advdebias reduces the attack accuracy to random guess ($\sim$50\%). For \adaptiveAIAHard, the theoretical bound on attack accuracy (\theoretical) matches with the empirical results (\empirical).} \label{fig:AdaptAIADebias} \vspace{-2mm} \end{figure*}