4 ms·
> Probably, but perhaps at the expense of a huge increase in false positives. "Perhaps" is a doing a lot of heavy lifting in your comment, and I find the possi
by coder543 4y ago
> Probably, but perhaps at the expense of a huge increase in false positives.
"Perhaps" is a doing a lot of heavy lifting in your comment, and I find the possible outcome you describe to be very unlikely after looking at the pictures in the article.
Personally, I'm confident that these anti-AI patterns don't work consistently across different person detection models, even though the article doesn't even ask the question, let alone dig into the answer.
The article doesn't present independent evidence that these work at all, let alone against more than just a single toy model built for PoC purposes.
It's an idea that gets clicks, and the oddly-specific "$71" (just an unnecessarily specific conversion from 500 yuan) also helps with attracting clicks. This article is basically just clickbait, in my opinion, not anything substantial.
- falcolas 4y agoThis is based (or independently developed alongside) CV Dazzle, which makes it harder for algorithms to identify "human" features by obscuring the edges they rely upon. The original Dazzle camouflage was effective against human eyes too, so there's a pretty high bar for making an algorithm dazzle-proof.
- coder543 4y agoThis is not doing anything to the edges, and it does not make it harder for me to see the person on the left, at all: https://petapixel.com/assets/uploads/2022/12/cad42d4d39741ca0eef7fd3f6528bf11-800x469.jpeg https://petapixel.com/assets/uploads/2022/12/cad42d4d39741ca... Additionally, most "cvdazzle" results on Google images are trying to obscure the face, not the existence of a person. This research is apparently focused on preventing a person from being detected, not obscuring their face with weird patterns. Even then, the "cvdazzle" stuff that I'm seeing does not make it harder for me to tell there's a person there. It has the same effect of obscuring identity as a ski mask.
- falcolas 4y agoI'm referring more to the jackets with the dark IR spots. The one you've linked is definitely using a different weakness of the CV they're using.
- coder543 4y ago>>> The original Dazzle camouflage was effective against human eyes too > I'm referring more to the jackets with the dark IR spots. Can your cite your source? Googling for "cvdazzle jacket" turns up nothing. "Dazzle jacket" just turns up a bunch of fashion stuff. Plus, nothing I've seen from the article -- including the dark IR spots jacket -- is that difficult to identify as a human, so the bar doesn't seem that high.
- falcolas 4y agohttps://cvdazzle.com/ https://cvdazzle.com/ https://en.wikipedia.org/wiki/Dazzle_camouflage https://en.wikipedia.org/wiki/Dazzle_camouflage
- coder543 4y agoOnce again, cvdazzle seems focused on obscuring a human face, not obscuring the existence of a human, and I don't see how it is more effective than a ski mask. A choice quote from your cvdazzle link: > This face is unrecognizable to the Viola-Jones Haar Cascade face detection algorithm. (It does not apply to DCNN face detectors) So... modern face detectors don't even have trouble with cvdazzle. All four of the detectors in this sample correctly identify the cvdazzled subject from the cvdazzle link: https://huggingface.co/spaces/celebrate-ai/face-detection-cnn https://huggingface.co/spaces/celebrate-ai/face-detection-cn... I'll also add a few choice quotes from Wikipedia: > Unlike other forms of camouflage, the intention of dazzle is not to conceal but to make it difficult to estimate a target's range, speed, and heading. > The result was that a profusion of dazzle schemes was tried, and the evidence for their success was, at best, mixed. So, no, dazzle camo does not seem to have a record of being effective against either humans or cameras, so the bar is low to start with, not "pretty high" at all. But, the goal here is also concealment, not obscuring range, speed, or heading, which dazzle camo only had "mixed success" for, and dazzle camo was never designed for concealment at all. In either case, I'm not talking about hiding a ship on the horizon. I'm talking about the effectiveness of this for hiding a human walking in front of a camera. What was the goal here? Dazzle camo seems like it was never proven to be that useful, according to wikipedia, and cvdazzle is obsolete according to its own website and a quick test that anyone can perform. As I said from the beginning, the article OP linked appears to be nothing more than clickbait. That $71 coat is not a general solution to AI surveillance, and training a machine learning model to detect it would not make that model suddenly overwhelmed with false positives.
- A4ET8a8uTh0 4y agoAs much as I dislike where this conversation is going ( edit: not this article; just our privacy expectations in general ), I am inclined to agree. Beyond the obvious, as the cat and mouse game continues, people who want to defeat it will need to account for almost inevitable increased number of algo variants and it is unlikely that: 1. They are mutually exclusive 2. They can't be run in close succession 3. They are disclosed and known to the person that tries to avoid them
- oofbey 4y agotl;dr: These tricks work pretty reliably against budget AI systems. But not good ones. The surprising truth is that these camouflage anti-patterns often work across many AI models. It's been a fairly baffling result in many research papers that the same trick-images work regardless of the model, but with an important catch... The models need to have been trained on the same dataset. If the model was trained on COCO (super common for finding objects in an image), then you can fool it. Since there are a handful of academic datasets that underlie a ton of CV models, these tricks will often work. But if the AI company used their own dataset to train the model, you can't fool it like this. (Unless you have an insider steal the dataset for you.) So if a company is good enough to come up with their own data, this doesn't work.
- astrange 4y ago"Model detects people and can be fooled" is a poor way to understand ML in the first place. It's actually "model detects people with an accepted false positive and false negative rate". Different amounts of necessary accuracy lead to completely different model architectures, so of course it's easier to fool one that's been made easier to be fooled.
- oofbey 4y ago> Different amounts of necessary accuracy lead to completely different model architectures Not really. For object detection, there are really only two kinds of architecture in common use - the multi-stage RCNN-style and the single-pass YOLO style. YOLO's are much faster, and not as accurate. But within each of these architectures, there's a big knob you can turn to trade-off speed vs accuracy. But the incredible truth is that those speed/accuracy trade-offs don't matter at all when facing an adversarial attack like this. The attacks will work reliably very well, as long as there are enough pixels and the t-shirt or whatever is facing the right direction, regardless of how the model is tuned for speed vs accuracy. That is, if you know the dataset it was trained on.