4 ms·
You're right. As far as I can tell all they have done is flip the image and then put out a press release that they've created some new technology to beat "AI" w
by shiftpgdn 5y ago
You're right. As far as I can tell all they have done is flip the image and then put out a press release that they've created some new technology to beat "AI" without actually doing anything. The average reporter is beyond non-technical and doesn't have the chops to suss out charlatans.
- potatoman22 5y agoLook up adversarial noise. That's a technology that can fool SOTA methods.
- kevin_thibedeau 5y agoFor specific models.
- baq 5y agoalways wondered why a low pass filter isn't a standard part of the training pipeline?
- gugagore 5y agoThe early convolution layers could implement a low-pass filter with the appropriate weights. Presumably the learning algorithm would do so if it were beneficial.
- baq 5y agoAnd yet there are tools to confuse networks with high frequency artifacts. If the network isn’t trained to ignore that, it won’t - but you don’t need a neural network to perform a low pass filter step if you can do that efficiently before asking the net what it sees on the already preprocessed image.
- KMnO4 5y agoAdversarial attacks rely on a specific model’s gradient (since you’re essentially trying to find the most sensitive pixels). Adversarial noise that affects model A won’t necessarily work on model B. That said, most people transfer train from well trained nets (ImageNet, Inception, etc). Finally, not all SOTA methods are susceptible to adversarial attacks, eg capsule networks.
- throw99901 5y ago>Finally, not all SOTA methods are susceptible to adversarial attacks, eg capsule networks. They appear to be susceptible: https://arxiv.org/pdf/1906.03612.pdf https://arxiv.org/pdf/1906.03612.pdf
- KMnO4 5y agoThat’s neat; hadn’t seen that paper. Thanks for sharing.