\begin{figure} \centering \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf} \caption{Census (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf} \caption{Census (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf} \caption{Compas (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf} \caption{Compas (sex)} \end{subfigure} \centering \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf} \caption{Meps (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf} \caption{Meps (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf} \caption{Lfw (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf} \caption{Lfw (sex)} \end{subfigure} \caption{For \AIAHard, we observe that EGD reduces the attack accuracy to random guess ($\sim$50\%)} \label{fig:AdaptAIAEGD} \end{figure} \begin{figure}[!htb] \centering \footnotesize \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf} \caption{Census (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf} \caption{Census (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf} \caption{Compas (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf} \caption{Compas (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf} \caption{Meps (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf} \caption{Meps (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf} \caption{Lfw (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf} \caption{Lfw (sex)} \end{subfigure} \caption{For both \AIASoft and \AIAHard, Adversarial debisaing reduces the attack accuracy to random guess ($\sim$50\%). For \AIAHard, the theoretical bound on attack accuracy matches with the empirical results.} \label{fig:AdaptAIADebias} \end{figure} \begin{figure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf} \caption{Census (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf} \caption{Census (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf} \caption{Compas (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf} \caption{Compas (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf} \caption{Meps (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf} \caption{Meps (sex)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf} \caption{Lfw (race)} \end{subfigure} \begin{subfigure}{0.24\linewidth} \includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf} \caption{Lfw (sex)} \end{subfigure} \caption{adverarial debiasing hard} \label{fig:aia-adv-hard} \end{figure}