6 ms·
Open Questions about Generative Adversarial Networks
- tasdfqwer0897 8y agoHey, I wrote this! Happy to answer questions.
- clickok 8y agoYou mention possible score functions in Problem 5, so I have a query about that. This has been bugging me for a bit-- is there a characterization of applicable loss functions for GANs? I'm curious about their effects on the results, but also if there's room for different losses. Or do we capture most desirable behavior using the listed score functions?
- tasdfqwer0897 8y agoHmm, I'm not sure what you mean by applicable loss functions? I'll answer what I think you're asking and you can tell me if I got it wrong: There's been a lot of effort spent on coming up with different loss functions for GANs, but https://arxiv.org/abs/1711.10337 https://arxiv.org/abs/1711.10337 shows that, according to the metrics in problem 5, they don't really improve results compared to the original GAN loss function. There's something called a Wasserstein GAN https://arxiv.org/abs/1701.07875 https://arxiv.org/abs/1701.07875 that you may have heard about, but IMO the useful thing to take away from that paper is their 'gradient penalty' technique and not the new loss function.
- woliveirajr 8y agoI'm interested in using GAN as a method to make authorship attribution more robust. Using complex NN models (let's say, LSTM) doesn't give much better results than simple neurons with deep layers. Seems that the model extraction (how to represent some author style) is the only point that matters, and it then easily forged (i.e., not hard to reproduce the desired style on purpose). I'm trying to use GAN as a mean of desconstruction, of removal of the ease patterns to see if some NN can use subtle characteristics to identify the author.
- tasdfqwer0897 8y agoSo you are worried that your existing attribution method is too focused on 'obvious' attributes and you want to see if you can make it focus on less obvious things? IIUC, that's something that's been looked at in the ML Fairness literature. See this paper for example: http://www.aies-conference.com/wp-content/papers/main/AIES_2018_paper_162.pdf http://www.aies-conference.com/wp-content/papers/main/AIES_2...
- formalsystem 8y agoSo let's say I'm in a regime where I'd like to train something like a language model RNN on a private text dataset. If I train the RNN directly on the data then I'm essentially leaking private data to the output. Do you know of any approaches to generate fake data using GANs, train a language model on that fake data and still get a good classifier that does well on test data while still quantifying how much private data is being leaked? Related: do GANs work well as a data augmentation technique and can their exact contribution to how much a model could potentially be improved be quantified. EDIT: Added some clarifications
- p1esk 8y agoYou can train rnn on encrypted data
- formalsystem 8y agoSure but the output would still leak data. E.g: You give the RNN the phrase "Chase Bank" and it outputs "Sell the stock". Encrypting the data secures the data loading part but it's not like your model didn't learn anything.
- p1esk 8y agoThe output would be encrypted of course. You’d decrypt it on your end. Whoever hosts the model can’t know what it learned, without breaking your encryption.
- yorwba 8y agoUnless you use fully homomorphic encryption (way too expensive for machine learning), the model can't learn anything without breaking your encryption. So you fixed the leak only at the cost of making the model completely useless.
- p1esk 8y agoSource? Unless the encryption actually destroys information I don’t see why it would necessarily make the job harder for the rnn.
- RSchaeffer 8y agoWhy is a VAE not a generative model?
- govg 8y agoThey are generative models.
- tasdfqwer0897 8y agoSomeone on the machine learning reddit asked me this: > Question: How does copyright work for GAN output? If I input 300,000 copyright protected photos of celebrities and generate images of new celebrities that do not exist, are the generated images public domain or would there be copyright issues? AFAIK, this is not a settled issue, but I'd be really interested hear what an actual lawyer thinks about this?
- mikehollinger 8y agoI’m curious as well. I imagine the definition of “derivative work” might be an interesting sub-problem to resolve while trying to answer the original question.
- tasdfqwer0897 8y agoSo if you wave your hands enough, it seems like maybe there's an argument to be made that the weights of a trained GAN somehow correspond to a 'compilation' of the training data as it's defined in this doc: https://www.copyright.gov/circs/circ14.pdf https://www.copyright.gov/circs/circ14.pdf
- genai 8y agoWith a compilation, you are able to find the original sources, but with a GAN is it even possible to find the original sources based on an output result alone?
- genai 8y agoHow would you even prove “derivative work”? My understanding is that in proving derivative work you would need to show the original, but in a GAN output which could be made up of 20MM nodes you would not even be able to confirm which 200K image(s) where used in the production of the output result
- tasdfqwer0897 8y agoThis actually might have interesting connections to ideas from differential privacy. Maybe the work is derivative of a particular training image if we can easily predict the presence or absence of that training image given only the trained model?
- Reelin 8y agoSlightly tangential question, but this is yet another piece of work published on Distill. I keep a library of the papers I've read in Zotero. However, when it comes to Distill I've run into a problem - I can't figure out a robust method of archival. Regular journal articles are published as PDF files, which make a decent electronic analog of physical paper. In the case of Distill, there's the usual DOI, volume, and issue, but the page itself isn't static. I did find a seemingly undocumented feature referenced in a GitHub issue - you can append "index.archive.html" to the url to get a supposedly standalone html archive of the page. However, when I tried this with a number of recent publications there were missing images and broken formatting all over the place, seemingly due to the authors having linked in external resources (primarily for a number of the figures). Does anyone know how to do this or have any ideas?
- phreeza 8y agoHaven't tried it on distil, but maybe this works? https://github.com/jgm/standalone-html https://github.com/jgm/standalone-html
- Reelin 8y agoLooks interesting, I'll try it out when I get a chance. I suspect it functions in a similar manner to Zotero's built in archiver though, so I'm not optimistic about what the results will look like.
- RustingSword 8y agoI use Zotero with [Zotero Connector](https://www.zotero.org/download/connectors https://www.zotero.org/download/connectors) plugin for Firefox. When saving a webpage to Zotero, it will also save a snapshot of that webpage (a configurable option in Zotero preferences). I tried it with latest two Distill posts, and didn't see any missing images. Actually for those interactive images, there will be a static version and an interactive version of that image in the snapshot, which is acceptable for me. Another problem more annoying is that those inline citations will show up even if you don't hover over them, thus covering underlying texts.
- dmix 8y agoOff-topic but I love the design of this blog article. Everyone is copying Medium these days so it's refreshing to see a smaller-typed and denser design for once.