datasets
Training and evaluation data, with the modality, task and licence stated up front. Listed live from the Hugging Face Hub.
AttackViz
AttackViz
AttackViz is a chart-image dataset for studying correct and misleading data visualizations. It was introduced in the paper ChartAttack: Testing the Vulnerability of LLMs to Malicious Prompting in Chart Generation.
Each example contains a rendered chart image, metadata about the chart and question type, the expected gold answer, a binary label indicating whether the chart is correct or misleading, a misleading-visualization category, and serialized chart annotations.… See the full description on the dataset page: https://huggingface.co/datasets/INSAIT-Institute/AttackViz.xai-attack-detection-cifar10
XAI Attack Detection — CIFAR-10 PGD
This private research dataset contains balanced, paired clean and adversarial images for
studying whether an attack can be detected from a classifier explanation map.
Dataset construction
The source is the CIFAR-10 test split. A fine-tuned OpenCLIP ViT-B/16 classifies each
clean image. Clean-correct examples are attacked with untargeted L-infinity PGD using
epsilon 8/255, step size 2/255, 10 steps, and deterministic random… See the full description on the dataset page: https://huggingface.co/datasets/nimaeb/xai-attack-detection-cifar10.demon_attack_mixed_0246_ghost30_200epAttackViz_extensionABRobOcular_Attacks
ABRobOcular: Ocular Adversarial Dataset
This repository contains the official public dataset for the paper: Adversarial benchmarking and robustness analysis of datasets and tools for ocular-based user recognition funded by the NSF award no. 2345561.
Paper: Neurocomputing 2025 ABRobOcular
Code: Bharath-K3/ABRobOcular
Figure: A taxonomy of adversarial attacks and defenses in ocular biometrics categorizing attacks into white-box (e.g., BIM, CW, FGSM, MIM, PGD) and black-box (e.g.… See the full description on the dataset page: https://huggingface.co/datasets/BharathK333/ABRobOcular_Attacks.demon_attack_mixed_0246_raw_200epxai-attack-detection-imagenette
XAI Attack Detection: Imagenette targeted BIM/PGD on ViT-B/16
Private research dataset of paired clean and targeted adversarial Imagenette images. It is
built to study how adversarial attacks change a Vision Transformer's explanation maps and to
support later work on attack detection. Each row is one source image with its clean and its
attacked version.
Summary
Pairs
12,420 (train 8,690 · validation 1,860 · test 1,870)
Source images
Imagenette v2… See the full description on the dataset page: https://huggingface.co/datasets/nimaeb/xai-attack-detection-imagenette.demon_attack_200ep_context5physical_attack_vla
Physical Visual-Prompt-Injection Attacks on Driving VLAs
16 safety-critical examples where a physically attacker-placeable artifact (a banner,
sign, held board, vehicle decal, or road paint — no real-infrastructure tampering) hijacks the driving
VLA AutoDrive-R2-7B on Waymo Open Dataset E2E (val) into a dangerous, wrong action.
Curation rule. Each cue is anomalous / fabricated (clearly not a real device or obstacle, so it is
distinguishable from a normal scene) yet drives a… See the full description on the dataset page: https://huggingface.co/datasets/gray311/physical_attack_vla.demon_attack_200epdemon_attack_ghost60_200epdemon_attack_fixed_latency_6_200ep_7k2steps_ghost15demon_attack_parquet2demon_attack_ghost15_200epdemon_attack_fixed_l2_fs1demon_attack_fixed_l2_fs2demon_attack_fixed_l2_fs6demon_attack_ghost30_200eppatch-attacks-defenses-with-vitscoco_attacked_eclipCIFAR10-PGD-attack-ResNet18Details are here: CIFAR10-subset-dataset-with-PGD-attacks-on-ResNet18
demon_attack_zero_latency_parquetdemon_attack_fix_latency_2demon_attack_fix_latency_6demon_attack_fix_latency_9demon_attack_fix_latency_15demon_attack_fix_latency_13demon_attack_mixed_latency_min_0_max_7demon_attack_fix_latency_5demon_attack_fix_latency_1
