3 ms·
This article relies on carefully constructed images that maximize one particular outcome by summing up lots of small errors into it. For it to work, the pixels
by Quanticles 11y ago
This article relies on carefully constructed images that maximize one particular outcome by summing up lots of small errors into it.
For it to work, the pixels have to be very accurately tweaked. If the tweaks were off by one pixel, the whole thing would fall apart.
The assumption is that this cannot be done to a person. But there is no way to put in a pixel-level "exploit of sorts" into a person to test that theory.
The real answer is probably that a little bit of noise on the input probably disrupts the exploit. It could never happen to a person because eyes have noise. At the same time, it could never happen to a robot either because cameras have noise.
- eru 11y agoFrom the article: Such screwy results can’t be explained away as hiccups in individual computer systems, because examples that send one system off its rails will do the same to another. After he read “Deep Neural Networks Are Easily Fooled,” Dileep George, cofounder of the AI research firm Vicarious, was curious to see how a different neural net would respond. On his iPhone, he happened to have a now-discontinued app called Spotter, a neural net that identifies objects. He pointed it at the wavy lines that Clune’s network had called a starfish. “The phone says it’s a starfish,” George says. Spotter was examining a photo that differed from the original in many ways: George’s picture was taken under different lighting conditions and at a different angle, and included some pixels in the surrounding paper that weren’t part of the example itself. Yet the neural net produced the same extraterrestrial-sounding interpretation. “That was pretty interesting,” George says. “It means this finding is pretty robust.” In fact, the researchers involved in the “starfish” and “ostrich” papers made sure their fooling images succeeded with more than one system. “An example generated for one model is often misclassified by other models, even when they have different architectures,” or were using different data sets, wrote Christian Szegedy, of Google, and his colleagues.4 “It means that these neural networks all kind of agree what a school bus looks like,” Clune says. “And what they think a school bus looks like includes many things that no person would say is a school bus. That really surprised a lot of people.”