3 ms·
Simulated data is provably more vulnerable to adversarial attacks. It only gives the illusion of more data (quite literally), and should not be used for mission
by jeromebaek 7y ago
Simulated data is provably more vulnerable to adversarial attacks. It only gives the illusion of more data (quite literally), and should not be used for mission-critical debiasing. A NN trained on mostly simulated minority faces and mostly real non-minority faces is a nightmare, the worst of both worlds: a plausible deniability that the algorithm is unbiased, and extreme susceptibility to adversarial attacks that take advantage of this illusory unbiasedness.