4 ms·
Took both versions of a lady on a yellow background photo, flipped the altered one horizontally and overlapped them in Photoshop. Looking now at the layer diffe
by ivanhoe 5y ago
Took both versions of a lady on a yellow background photo, flipped the altered one horizontally and overlapped them in Photoshop. Looking now at the layer difference and I see nothing other than slight outline highlight and some artifacts on the background (that can easily be cropped). The faces are identical, none of the biometrical features has been altered, once you flip the photo back to normal orientation, it's basically the same photo - diff is almost completely black.
- shiftpgdn 5y agoYou're right. As far as I can tell all they have done is flip the image and then put out a press release that they've created some new technology to beat "AI" without actually doing anything. The average reporter is beyond non-technical and doesn't have the chops to suss out charlatans.
- potatoman22 5y agoLook up adversarial noise. That's a technology that can fool SOTA methods.
- kevin_thibedeau 5y agoFor specific models.
- baq 5y agoalways wondered why a low pass filter isn't a standard part of the training pipeline?
- gugagore 5y agoThe early convolution layers could implement a low-pass filter with the appropriate weights. Presumably the learning algorithm would do so if it were beneficial.
- baq 5y agoAnd yet there are tools to confuse networks with high frequency artifacts. If the network isn’t trained to ignore that, it won’t - but you don’t need a neural network to perform a low pass filter step if you can do that efficiently before asking the net what it sees on the already preprocessed image.
- KMnO4 5y agoAdversarial attacks rely on a specific model’s gradient (since you’re essentially trying to find the most sensitive pixels). Adversarial noise that affects model A won’t necessarily work on model B. That said, most people transfer train from well trained nets (ImageNet, Inception, etc). Finally, not all SOTA methods are susceptible to adversarial attacks, eg capsule networks.
- throw99901 5y ago>Finally, not all SOTA methods are susceptible to adversarial attacks, eg capsule networks. They appear to be susceptible: https://arxiv.org/pdf/1906.03612.pdf https://arxiv.org/pdf/1906.03612.pdf
- KMnO4 5y agoThat’s neat; hadn’t seen that paper. Thanks for sharing.
- kolinko 5y agoIt’s even worse than that. I pasted the photo verbatim into the first online face recognition tool I could find. Found the face with no problem whatsoever. https://imgur.com/gallery/5beg8qg https://imgur.com/gallery/5beg8qg
- SamBam 5y agoI don't think there doing it can't detect the existence of faces, rather that they can't recognize them. But this appears to be utter BS. They're not showing the results of a facial defection system, they're simply sticking it in TinEye. TinEye is a tool that helps you find the same photo elsewhere, it has absolutely zero, zip, zilch to do with facial detection.