Papers › Foolbox: A Python toolbox to benchmark the robustness of machine learning models

Foolbox: A Python toolbox to benchmark the robustness of machine learning models

13 Jul 2017arXiv:1707.04131archive 2025-07-28

Jonas Rauber, Wieland Brendel, Matthias Bethge

Even todays most advanced machine learning models are easily fooled by almost imperceptible perturbations of their inputs. Foolbox is a new Python package to generate such adversarial perturbations and to quantify and compare the robustness of machine learning models. It is build around the idea that the most comparable robustness measure is the minimum perturbation needed to craft an adversarial example. To this end, Foolbox provides reference implementations of most published adversarial attack methods alongside some new ones, all of which perform internal hyperparameter tuning to find the minimum adversarial perturbation. Additionally, Foolbox interfaces with most popular deep learning frameworks such as PyTorch, Keras, TensorFlow, Theano and MXNet and allows different adversarial criteria such as targeted misclassification and top-k misclassification as well as different distance measures. The code is licensed under the MIT license and is openly available at https://github.com/bethgelab/foolbox . The most up-to-date documentation can be found at http://foolbox.readthedocs.io .

PaperPDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

bethgelab/foolbox officialmentioned in papermentioned on GitHubtfMIT report
EvgeniaAR/foolbox mentioned on GitHubtf report
alvarorobledo/fyp-foolbox mentioned on GitHubtf report
bbwang1030/half-kfn mentioned on GitHubjax report
deqncho2/foolbox-adversarial mentioned on GitHubpytorch report
pralab/secml mentioned on GitHubpytorchApache-2.0 report
gitlab.com/secml/secml mentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial AttackBIG-bench Machine Learning

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections