How to trick a neural network into thinking a panda is a vulture
codewords.recurse.com
codewords.recurse.com
It suggests that because neural networks cannot properly separate the classes, the often mush them together in the input-space so the "panda" region of image-space has loads of other classes speckled though it. If you purposely find those speckles you can make it think that a panda is a vulture.
That blog mentions adding smoothness constraints, so that you can't suddenly go from panda to vulture with a tiny change in an image. But I wonder if an easier solution (ok, hack) is just to add different noise to the image 10 times or so, run it through the network and then combine the results.
Essentially you'd be doing Monte Carlo sampling of the image space around the input image. Or kind of blurring the image space.
Just an idea anyway. I don't really know what I'm talking about.
There are multiple options to try to enhance the distance to the decision boundary (such as the adversarial examples referenced in the post), but I think the recent work from microsoft (I think it's published Dec 2015) on replacing pooling layers in the convolutional neural net with something analogous random forests might be the best option so far. More or less each decision tree will end up pushing values to 0/1 in the non-linear region, which mitigates some of the concern about overly linear systems and it places the decision boundary at a somewhat arbitrary location between classes. In aggregate when these locations are combined the resulting classifier has a larger margin without explicitly needing adversaries. So instead of sampling the image space, you're effectively sampling the classifier space.
If you want, I can dig up the citation, but searching for deep neural nets and random forests should get you to the paper all the same.
http://research.microsoft.com/pubs/255952/ICCV15_DeepNDF_mai...
From abstract:
"(...) we introduce a stochastic and differentiable decision tree model, which steers the representation learning usually conducted in the initial layers of a (deep) convolutional network. (...)"
http://i.imgur.com/NdzdH5j.png
On the left are the training vectors, color-coded by label; the background color-codes the probability output by the learned network at each point in the plane. On the right is the gradient field of the network's output corresponding to the blue class. The gradient field shows, at any point, the local direction of greatest increase toward the blue class.
Rank the image by entropy, and re-run the neural network centered on those points with a radially-increasing gaussian blur applied to the subimage (approximating the sensitivity of the human visual field).
https://en.wikipedia.org/wiki/The_Man_Who_Mistook_His_Wife_f...
Pre-processing seems to be an answer, normalize the image, blank out areas obviously uninteresting to human eye, add dithering.
Also, it kind of defeats the purpose of neural networks to do substantial feature engineering like that.
Blanking out areas that are "not of interest" I would consider substantial feature engineering (unless the task you were training a net for was explicitly to find interesting vs. uninteresting areas).
Our human eyes have a lot of filters (hardware and software-based) before recognition takes place.
I currently work on estimating emphysema extent in CT lung scans. Emphysema can be very diffuse and it is not possible to label individual pixels, so instead we try to learn the local emphysema pattern from a global label. Neural networks are interesting for this problem because the learn the features, but it is also a "problem" because the features might not make physically sense, which could make it hard to transfer the model and convince clinicians that they should use it.
We should just be realistic. We want to take real image, except it might be tinkered with, and make neural net tell us what we see on it, except we also want it to see what we can't see, and we want it to answer as accurate as possible, except we also want short and definitive answer.
We also kind of want it to admit that image always contains more than one thing, but kind of don't.
You won't win much by making every neural network learn stuff from scratch that can be done once, good.
[I 08:37:21.591 NotebookApp] Writing notebook server cookie secret to /.local/share/jupyter/runtime/notebook_cookie_secret
[I 08:37:21.757 NotebookApp] Serving notebooks from local directory: /neural-nets
[I 08:37:21.758 NotebookApp] 0 active kernels
[I 08:37:21.759 NotebookApp] The IPython Notebook is running at: http://0.0.0.0:8888/
[I 08:37:21.759 NotebookApp] Use Control-C to stop this server and shut down all kernels (twice to skip confirmation).
What next? Should I be looking for a python notebook tutorial, or a docker tutorial, or both?The author lists some commands to run, but it isn't clear where to type those commands. All I see is a terminal with the above output.
i won't claim that all networks overfit the data, but i suspect the methods tend to be prone to overfitting more than other methods that have far less parameters to optimise.
this doesn't really matter in order to generate a bunch of fun pictures and visualisations.
It shows that a human brain is just a neural network with decades of training.
Regardless, this has nothing to do with how the brain learns, but rather the function it has learned. Even if a neural network somehow used entirely local learning rules, it could still be exploited with this method.
The learning rule and the hypothesis class together dictate what sort of function is learned.
>Even if a neural network somehow used entirely local learning rules, it could still be exploited with this method.
Yes, which is why current neural networks may not be the best learning method.
But we can't try every possible set of inputs to human eyes. So we don't actually know how fragile human brains are. I suspect that brains use similar tricks to artificial neural networks, and learn similar functions.
I don't think any humans are going to be fooled by this procedure, so what algorithm do people use to classify? There must be other algos out there that are more plausible as explanations for what humans (and animals) use?
Personally, it seems very plausible to me that humans and animals use generative modeling (which was behind the "human-level concept learning" paper published this month) rather than discriminative (like typical neural networks).
For what it's worth, of all the intelligent things the human brain performs, the visual system is the system that is closest to what neural nets are doing.
For example, humans have access to facts, which allow for better use of context information. E.g. I know that pandas live in trees, and that the queen wears a crown.
It does appear that humans do better with limited training data. I have probably seen fewer pandas than the NN in the article, but I can identify them more reliably. It probably comes down to humans' superior ability to generalize training examples.
So for a human the question is more like: Does it have a shape like a Panda, does it have a face like a panda, does it have fur like a panda, and does it have coloring similar to a panda? Then it probably is a panda.
I also don't believe all of these systems are trained neural networks, but rather some of them are evolved instincts, hardwired and (near) unchangeable during a lifetime. Perfected over millions of years.
Well that's the thing, it's a bit of a philosophical paradox/conundrum actually :)
See, you can subtly tweak these images up to the point where an artificial neural network is really sure that it's a vulture and not a panda. It scores real high on "vulture", not just slightly over the threshold, it's possibly to push it far into "most definitely a vulture" score.
And--someone correct me if I'm wrong--I think I remember from other research that if you tweak an image into another category using the gradients of one neural net, it still scores very high on that other category if you try to classify it with a different neural net.
While our own biological neural network ... well, as you look at the image, you're really sure that it's a panda and not a vulture.
Now imagine the opposite. Let's assume we can fool our own biological neural networks in a similar manner. What would this experience be like?
Imagine you observe an image that to your eyes (or visual cortex) most definitely looks like a panda. Except it "actually", "really" is a picture of a vulture.
The question then becomes, if it looks like a panda to our biological/human neural networks, who or what is the authority that can say "no you are mistaken, this is actually a picture of a vulture, it just seems like a panda to your brain"?
Because it will fool human neural networks, most people will agree "yup looks like a panda to me".
So if all the humans are wrong, who gets to say what it "really" is a picture of? Maybe an artificial neural network? :-) Because we already have one of those. It's in the article. There's that picture that to our puny mistaken human neural nets definitely looks like a panda. But the artificial neural net in the article sees the "really real truth" and tells us that no, it really is a picture of a vulture, really, with mathematical certainty. ("wake up sheeple!", etc ;-) )
she.
"Can you classify this image of a panda? Oh, curious, it thinks it is a vulture..."
For example, one story involved training a classifier to recognize an overhead image with tanks vs without. It turns out it ended up learning which days were sunny and which were overcast.
This sort of thing happens when training people from examples too: From the mundane cases in school, to the AA587 crash in Queens NYC.
The earliest source I can find for this is https://neil.fraser.name/writing/tank/ but it says it "might be apocryphal".
http://i.imgur.com/fJ35PTc.png
It's kind of confusing, but table 2 shows what percent of these adversarial images trained on one networked worked on another. It varies quite a bit, and many networks aren't similar enough to each other for it to work reliably. But there is definitely some degree of generalization.
> So now we’ve seen the network do a correct thing, and we’ve seen it make an adorable mistake by accident (the queen is wearing a shower cap ).
This is such a Julia sentence, including the suddenly appropriate emoji, it should probably have clued me in.
Edit: HN is breaking my heart with its anti-emoji stance, so (re)read the article to see the quote in its full glory.
zero understanding of something so simple, laid out as black magic. And a lot more time spent fiddling with the thing as a toddler playing with a toy than it would be required to read two or three articles that explained it correctly.