Optical illusions that flummox computers
theverge.com
theverge.com
If neural networks are here to stay, maybe we should slow down their public deployment for a moment and understand them better first. It would be ideal to find fundamental structural/algorithmic changes that can harden them rather than relying on heuristics or other "wrappers" to make input/output safe to use in autonomous environments. The more that is "extra", the less those security features will be implemented. (We see this rampantly on the web today with HTTPS.)
Should we wait till something is perfect before we deploy? Should we hold back on self driving cars until the tech is completely foolproof? What about the number of accidents/deaths that could be prevented by even a flawed autonomous car?
Sometimes insecure and imperfect now is better than delaying a technology years until it can be 'perfected'.
Putting a great deal of reliance on a system in that situation seems like a great mistake. "It looks like it works under normal circumstances" is not very reliable.
It's fun to imagine someone constructing adversarial examples to cause self-driving cars to crash. But is that really a big deal? Humans can just as easily be tripped up by an "adversarial" example: I can pretty easily point a laser pointer from my window at random humans driving a car. The legal system has well-defined mechanisms for dealing with this.
The recognition systems look like they are doing the same thing we are, but they're not. Adding an adversary taking advantage of the difference is just sauce on top of the problem.
The Internet faced the problem of harnessing the power of computer networks required a critical mass and that none of the "ideal" conceptions could achieve this (especially since "ideals" usually didn't understand the full potential of the system). Here "worse is better" made sense.
Neural Nets and related systems are deployed by large companies with lots of data and used to provide guidance and decision making (where network effect isn't a big factor either way).
With "guidance" - product recommendations or optional translations, the dangers seem relatively small. With decision making systems, the dangers seems considerable and not totally thought through - you have everything from people falsely flagged by face-recognition software to neural networks that derive racist loan policies to the spoofing potential that management recommendation engines might offer.
Could you spoof a stock decision system by making a series of stock trades that has previous preceded a big move? I don't know but I assume someone is thinking of ways to use neural spoofing to get something from someone as we speak.
What I believe the grandparent said was we should slow-roll neural networks where they have severe consequences, as in, life and death.
I agree, slow-rolling the internet would have potentially affected adoption, but the stakes are lower than, say, a self-driving car going off the rails. In those cases, we should probably thoroughly understand how a car can be affected by adversarial attempts at "breaking the algo" before adopting it very widely.
In other words, I wouldn't slow roll the internet because of fears of adversarial behavior, but I would in the face of self-driving cars.
I hope that further discussion could describe how internet security is as life-and-death as self-driving cars, or to the contrary :)
> maybe we should slow down
Please submit your proposal after the one for slowing down population growth, but before your one for slowing down general arms proliferation. Thanks.Less so, obviously, if you do something like downsample it or otherwise soften or ... with filters first. Nor do they fool neural networks with attention (they simply at some point decide it's not worth looking at and identify the picture by something else).
And the ridiculous example given does not work without being able to read the mind of the neural network (the misidentified panda).
Most neural network classification mistakes are "understandable" (e.g. look at the misidentified carousel). These are really 99.99% or more of the total mistakes make. Also that network probably needs more Indian elephants in it's training set (kids make stupid mistakes classifying animals they've never seen or only seen very few times as well [1]).
Given how a lot of animals look, I wonder if this doesn't work on "real" brains as well. I for one have trouble seeing zebras in pictures, and it's of course not for lack of contrast. Counting them or accurately judging distance is just out of the question. But many animals look way more colorful and contrast-rich than seems advisable, from chickens, of course peacocks, to ladybugs.
A number of optical illusions seem based on high contrast patterns being included in images. Especially if, like in the examples here, the high contrast patterns don't line up with the objects in the image (e.g. moving a vertical and horizontal slit filter over an image and you will not be able to see through it, however in any freeze frame you won't have that problem).
> The fact that the same fooling images can scramble the “minds” of AI systems developed independently by Google, Mobileye, or Facebook, reveals weaknesses that are apparently endemic to contemporary AI as a whole. [...] “All these networks are agreeing that these crazy and non-natural images are actually of the same type. That level of convergence is really surprising people.”
The machine learning systems will probably use similar tricks at some point. You might need to double the resource needed to process data twice or more, but you end up with a harder to fool systems. At least with the current adversarial attacks.
------------------
[0] https://www.scientificamerican.com/article/two-eyes-two-view...
[1] http://www.bbc.com/future/bespoke/story/20150130-how-your-ey...
Humans are bad at recognition but still the best there are.
Remark: I noticed that even a watermark in the lower-left of the image (as you see on TV) can totally mess up DL prediction.
Improvements in datasets, transfer learning, and online learning will help. Unfortunately this underscores the issue that giants such as google have more pictures of funny glasses than anyone else...
The design of networks is limited by the dataset, since researchers are just trying to hit the metric for the dataset. Better datasets will lead to better networks. Better data eventually means billions of cameras, for example.
The article was kind of interesting to me because it reveals that networks are probably sometimes making decisions on highly discriminating but non-essential stimulus features.
It's like the networks might have a high success rate with large number of replicated examples, over sample size, but not over a large number of distinct examples.
They're overfitting, but in a way that isn't immediately obvious because the test stimuli tend to be limited.
My guess is the answer is to incorporate into the training set a lot of quasi-random or structured but abstract images as controls for training.
The design of the network is a direct consequence of the dataset+metric because researchers focus on accuracy scores against the test data. Given a better dataset and metric, researchers will solve it with a better network design. I guarantee it.
But we don't actually know the real issue, do we? You can't easily debug a neural network. Sure, you can throw ten times more data at it and hope that fixes it. But the more data you throw in, the less you understand what's happening - which affects your ability to anticipate the next problem.
I am not sure I buy this theory. Moving an image across a nearby boundary shouldn't result in the image producing a higher confidence value, should it?
I'm thinking of the panda/gibbon example in the article.
By shifting it a few points across the boundary, it creates a higher confidence that X is actually Y instead of X.
The problem is that without studying the neural network and trying out different inputs and seeing the results, it's hard to figure out exactly what will shift things across the boundary. Even if you could get the same starting data set and attempt to train your own, you don't necessarily know which data was used for testing vs validation.
You'll likely come up with similar boundaries but not the same therefore you don't know the effectiveness of your adversarial approach until you actually try it against that particular system..
Totally what happens inside of a NN :D
> If we transfer adversarial examples from one model to another model trained with one of these defenses, the attack often succeeds, even when a direct attack on the second model would fail [PMG16].
http://www.cleverhans.io/security/privacy/ml/2017/02/15/why-...
The ease at which you can 'fool' machine learning right now adds an additional layer to practical machine learning in the wild - risks from malicious attacks.
Imagine someone putting up a lawn sign that tricks self driving cars into seeing something that isn't there and applying the wrong behavioral pattern because of it. Or even simpler, someone taping a sticker over the self driving car's cameras that cause erratic behavior. Can have really bad consequences and seems really simple to do.