🛡 torchattack - A curated list of adversarial attacks in PyTorch, with a focus on transferable black-box attacks.
pip install torchattack # or `torchattack[full]` to install all extra dependencies
Highlights
- 🛡️ A curated collection of adversarial attacks implemented in PyTorch.
- 🔍 Focuses on gradient-based transferable black-box attacks.
- 📦 Easily load pretrained models from torchvision or timm using
AttackModel. - 🔄 Simple interface to initialize attacks with
create_attack. - 🔧 Extensively typed for better code quality and safety.
- 📊 Tooling for fooling rate metrics and model evaluation in
eval. - 🔁 Numerous attacks reimplemented for readability and efficiency (TGR, VDC, etc.).
Documentation
torchattack's docs are available at docs.swo.moe/torchattack.
Usage
import torch
device = torch.device('cuda' if torch.cuda.is_available() else 'cpu')
Load a pretrained model to attack from either torchvision or timm.
from torchattack import AttackModel
# Load a model with `AttackModel`
model = AttackModel.from_pretrained(model_name='resnet50').to(device)
# `AttackModel` automatically attach the model's `transform` and `normalize` functions
transform, normalize = model.transform, model.normalize
# Additionally, to explicitly specify where to load the pretrained model from (timm or torchvision),
# prepend the model name with 'timm/' or 'tv/' respectively, or use the `from_timm` argument, e.g.
vit_b16 = AttackModel.from_pretrained(model_name='timm/vit_base_patch16_224').to(device)
inv_v3 = AttackModel.from_pretrained(model_name='tv/inception_v3').to(device)
pit_b = AttackModel.from_pretrained(model_name='pit_b_224', from_timm=True).to(device)
Initialize an attack by importing its attack class.
from torchattack import FGSM, MIFGSM
# Initialize an attack
adversary = FGSM(model, normalize, device)
# Initialize an attack with extra params
adversary = MIFGSM(model, normalize, device, eps=0.03, steps=10, decay=1.0)
Initialize an attack by its name with create_attack().
from torchattack import create_attack
# Initialize FGSM attack with create_attack
adversary = create_attack('FGSM', model, normalize, device)
# Initialize PGD attack with specific eps with create_attack
adversary = create_attack('PGD', model, normalize, device, eps=0.03)
# Initialize MI-FGSM attack with extra args with create_attack
attack_args = {'steps': 10, 'decay': 1.0}
adversary = create_attack('MIFGSM', model, normalize, device, eps=0.03, **attack_args)
Check out examples/ and torchattack.evaluate.runner for full examples.
Attacks
We roughly categorize transferable adversarial attacks into the following categories based on their strategies to improve adversarial transferability:
- Classic attacks: The line of work that first proposed gradient-based adversarial attacks.
- Gradient augmentations: Stabilizing or augmenting the gradient flows to improve transferability.
- Input transformations: Applying all forms of transformations as image augmentations to inputs.
- Feature disruption: Disrupting intermediate features of the surrogate model.
- Surrogate self-refinement: Refining the surrogate model, both structure-wise and in forward/backward passes.
- Generative modelling: Using generative models to generate adversarial examples.
- Others: Other attacks that do not fit into transfer-based attacks but are important black-box attacks.
We provide a detailed list of all supported attacks below.
Development
On how to install dependencies, run tests, and build documentation. See Development - torchattack.
License
Related
Metadata
Release files for torchattack 1.7.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| torchattack-1.7.2.tar.gz | 77.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| torchattack-1.7.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 193.5 kB
Release files / torchattack-1.7.2.tar.gz
| Download URL | torchattack-1.7.2.tar.gz |
|---|---|
| Size | 77.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
352e00d3f65172b7891fcbeafbff1ad94e740b665be2d45f24ae5e3bedce9db6
|
|
BLAKE2b-256 checksum How to use checksums |
3960d31fc4262bad841b0767c5991aa5e0eca5150fb221761d8e88ba91e8958d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 22, 2025.
Transparency logRelease files / torchattack-1.7.2-py3-none-any.whl
| Download URL | torchattack-1.7.2-py3-none-any.whl |
|---|---|
| Size | 116.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d9219527f96f621348c0c0196fea067224a16876e8982199710495f9f5799862
|
|
BLAKE2b-256 checksum How to use checksums |
27106e2507a5f158526ae287c70f5559bef89fdf30a1e69f1a59b2ce1783dba4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 22, 2025.
Transparency log