VATRA 2025
VATRA helps machine learning practitioners compare how models perform on ordinary images and images altered by adversarial attacks. Training a model to resist attacks can affect its accuracy and how evenly it performs across different classes. We developed VATRA through an iterative design process to make these trade-offs easier to explore, from overall model performance down to individual examples.
Recognition & Outreach
- Accepted to Graphics Interface 2025 and received a Best Paper Award. Read the University of Waterloo feature .
Core Features
- Compare model performance on ordinary and adversarial images.
- Move between model summaries, embedding views, and individual examples.
- Explore how adversarial training affects accuracy, robustness, and performance across classes.





Links
Paper Link
View on ACM Digital Library.
Award News
Read the Cheriton School of Computer Science news post.
Skills
- Python
- PyTorch
- Grad-CAM
- Visualization Design
- Machine Learning
- Evasion Attacks
- D3.js
- JavaScript
Keywords
- Adversarial Machine Learning
- Adversarial Training
- Visualization
- Model Robustness
- Accuracy-Robustness Trade-offs
Authors
Yuzhe You, Jian Zhao