Skip to main content

secml-torch   

SecML-Torch: A Library for Robustness Evaluation of Deep Learning Models

pypi py_versions coverage docs

SecML-Torch (SecMLT) is an open-source Python library designed to facilitate research in the area of Adversarial Machine Learning (AML) and robustness evaluation. The library provides a simple yet powerful interface for generating various types of adversarial examples, as well as tools for evaluating the robustness of machine learning models against such attacks.

Installation

You can install SecMLT via pip:

pip install secml-torch

This will install the core version of SecMLT, including only the main functionalities such as native implementation of attacks and PyTorch wrappers.

Install with extras

The library can be installed together with other plugins that enable further functionalities.

  • Foolbox, a Python toolbox to create adversarial examples.
  • Tensorboard, a visualization toolkit for machine learning experimentation.
  • Adversarial Library, a powerful library of various adversarial attacks resources in PyTorch.

Install one or more extras with the command:

pip install secml-torch[foolbox,tensorboard,adv_lib]

Key Features

SecML-Torch (SecMLT) is a PyTorch-native toolkit for evaluating and improving adversarial robustness. It provides:

  • Built-in support for evaluating PyTorch models.
  • Efficient native implementations of common evasion attacks (e.g. PGD, FMN), built directly for PyTorch, and poisoning/backdoor attacks.
  • Wrappers for external libraries (Foolbox, Adversarial Library) so you can run and compare attacks from a single interface.
  • Modular design to build adaptive/custom attacks to swap losses, optimizers, perturbation models, and add EoT easily with a few lines of code.
  • Attack ensembling modules to obtain worst-case per-sample robustness evaluations.
  • Robustness evaluation tools including metrics, logging, and trackers to ensure reproducibility and easy reporting.
  • Attack debugging support such as built-in hooks and TensorBoard integration to monitor and inspect attack behavior.

Check out the tutorials to see SecML-Torch in action.

Category Attack / Attack Type Native Implementation in SecML-Torch Wrapped / Imported / Backend Alternatives
Advantages: GPU-native, efficient, modular/customizable, debugging tools Advantages: expands the attack catalogue, easy cross-checks
Test time PGD (fixed-epsilon, iterative attack) ✔ Native implementation ✔ Also via backend wrappers (Foolbox, Adversarial Library).
Test time FMN (minimum-norm, iterative attack) ✔ Native implementation ✔ Also via backend wrappers (Foolbox, Adversarial Library).
Test time DDN (minimum-norm, iterative attack) ✔ Native implementation ✔ Also via backend wrappers (Foolbox, Adversarial Library).
Test time FGSM (Fast Gradient Sign Method) - ✔ Available via backend wrappers (Foolbox, Adversarial Library).
Test time CW (Carlini & Wagner L2) - ✔ Available via backend wrappers (Foolbox, Adversarial Library).
Test time DeepFool - ✔ Available via backend wrappers (Foolbox, Adversarial Library).
Test time VAT (Virtual Adversarial Training) - ✔ Available via backend wrapper (Foolbox).
Test time HopSkipJump (black-box attack) - ✔ Available via backend wrapper (Foolbox).
Test time Boundary Attack (black-box attack) - ✔ Available via backend wrapper (Foolbox).
Test time Spatial Attack - ✔ Available via backend wrapper (Foolbox).
Test time Additive Noise - ✔ Available via backend wrapper (Foolbox).
Test time Salt & Pepper Noise - ✔ Available via backend wrapper (Foolbox).
Test time Gaussian Blur - ✔ Available via backend wrapper (Foolbox).
Test time Contrast Reduction - ✔ Available via backend wrapper (Foolbox).
Training time Backdoor ✔ Native implementation -
Training time Label Flip Poisoning ✔ Native implementation -

Check out what's cooking! Have a look at our roadmap!

Usage

Here's a brief example of using SecMLT to evaluate the robustness of a trained classifier:

from secmlt.adv.evasion.pgd import PGD
from secmlt.metrics.classification import Accuracy

model = ...
torch_data_loader = ...

# create and run attack
attack = PGD(
    perturbation_model="l2",
    epsilon=0.4,
    num_steps=100,
    step_size=0.01,
)

adversarial_loader = attack(model, torch_data_loader)

# Test accuracy on adversarial examples
robust_accuracy = Accuracy()(model, adversarial_loader)

For more detailed usage instructions and examples, please refer to the official documentation or to the examples.

Contributing

We welcome contributions from the research community to expand the library's capabilities or add new features. If you would like to contribute to SecMLT, please follow our contribution guidelines.

Acknowledgements

SecML has been partially developed with the support of European Union’s ELSA – European Lighthouse on Secure and Safe AI, Horizon Europe, grant agreement No. 101070617, Sec4AI4Sec - Cybersecurity for AI-Augmented Systems, Horizon Europe, grant agreement No. 101120393, and CoEvolution - A Comprehensive Trustworthy Framework for Connected Machine Learning and Secure Interconnected AI Solutions, Horizon Europe, grant agreement No. 101168560, and by the project SERICS (PE00000014) under the MUR National Recovery and Resilience Plan funded by the European Union - NextGenerationEU.

sec4ai4sec    elsa    coevolution    serics    safer europe

Metadata

Release files for secml-torch 1.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secml-torch 1.5
File Size Uploaded
secml_torch-1.5.tar.gz 57.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secml-torch 1.5
File Interpreter ABI Platform
secml_torch-1.5-py3-none-any.whl Python 3 none any Details

Total release size: 161.7 kB

Release files / secml_torch-1.5.tar.gz

Download URL secml_torch-1.5.tar.gz
Size 57.2 kB
Tags Source
SHA-256 checksum
How to use checksums
25298ac226f9e47855ab4ef627f9f519c3d81de637a8d3251a93d14882f20111
BLAKE2b-256 checksum
How to use checksums
db97b480054dbf7f118528bc9ad0e75dbf0ead965daa0e89e3d14ffae3fd3b5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.

Transparency log

Release files / secml_torch-1.5-py3-none-any.whl

Download URL secml_torch-1.5-py3-none-any.whl
Size 104.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8c363efbbf39fefcb17ff115a4c604bed5159a10ab7ed5c5bbcf3a0d3c483012
BLAKE2b-256 checksum
How to use checksums
fa6261766ddcf7866816518c23bd6c86e9dfb66a4ec6a1c7fd9a01250f6f891a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.5 This release

2 release files

1.4

2 release files

1.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.0.0

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page