AdvEx 2024
AdvEx helps people new to machine learning explore adversarial attacks on image classifiers. These attacks make small changes to an image that can alter a model's prediction while remaining difficult for a person to notice. The tool lets you compare models and attack methods, inspect individual images, and explore patterns across a dataset to see where and how predictions change.
Recognition & Outreach
- Published in ACM Transactions on Interactive Intelligent Systems. Read the paper .
- Received third place in the poster competition at the University of Waterloo's 2024 Cybersecurity and Privacy Institute Annual Conference (300 CAD). Read the award announcement .
- Presented as a talk and poster at the University of Waterloo's 2023 Math and Computing Research Discovery Days.
Core Features
- Explore attacks such as FGSM, PGD, and ZOO through interactive views.
- Compare how different classifiers respond to the same attack.
- Inspect changes to individual images alongside patterns in model performance.




Links
Paper Link
View on ACM Digital Library.
Video figure
Short visual overview of the system.
Video demo
Full walkthrough of the interaction design.
CPI winner announcement
Recognized as a top 3 project at the CPI annual conference.
Skills
- Python
- PyTorch
- scikit-learn
- Machine Learning
- Evasion Attacks
- D3.js
- JavaScript
Keywords
- HCI
- Information Visualization
- Adversarial Machine Learning
- FGSM
- PGD
- Model Robustness
Team Members
Yuzhe You, Jarvis Tse, Jian Zhao