4 ms·
You may be interested in this talk: https://www.youtube.com/watch?v=tleeC-KlsKA#t=282 https://www.youtube.com/watch?v=tleeC-KlsKA#t=282 The speakers runs you t
by compbio 12y ago
You may be interested in this talk: https://www.youtube.com/watch?v=tleeC-KlsKA#t=282 https://www.youtube.com/watch?v=tleeC-KlsKA#t=282
The speakers runs you through a hypothetical case study: a pet-door company and looks at the pitfalls of applying machine learning to it.
I believe the paper is actually focusing on something else: Create images that humans will not be able to classify as a digit, but that the net will gladly give a prediction for. To translate to faces: There may be clouds that look random to our human brain, but are detected as faces by nets.
It seems this is an adversarial attack, where you need access to the guts of the net (weights, layers). I compare this with a hashing algorithm and brute-forcing the input till you find a collision with a target. Nearly impossible in real-life situations.
You may be able to sign a check using a scribble that the cashier can not recognize as a digit, but that the machine will recognize as a digit. Not much practical gain from an attack there.