Attacking Machine Learning with Adversarial Examples
blog.openai.com
blog.openai.com
If it interests anyone, I wrote up a bit about this and other threats related to machine learning models, a few weeks ago: https://matt.life/papers/security_privacy_neural_networks.pd...
Using a fail safe network is hard because adversarial examples usually have a high accuracy at a false class. So using an accuracy threshold in the main network wouldn't work. Using a network as described in the paper and then a different kind of classifier might be worth trying. But it has also been shown that adversarial examples can transfer to different kind of models (don't know if random forests have been tried as well).