BadNets: Identifying vulnerabilities in the machine learning model supply chain
blog.acolyer.org
blog.acolyer.org
They're ... undocumented and have specified behavior (leading to serious, not-hypothetical problems like racial bias). Their maintenance is unspecified or nonexistent. They inherently have security holes in a multitude of fashions. Their performance isn't guaranteed and measured only against their own benchmarks, etc...
This kind of thing is much more of a problem when they have to be a system used by a large institution as just part of its operations (a loan evaluation program or a recidivism indicator) rather than a standard alone application (a program to play the game of go). But in the former capacity, a lot more work needs to be done.
Maybe i'm just scare mongering or worrying about nothing. I just don't really feel comfortable putting my life in the hands of something that no one knows exactly how it works.
That, and obviously it would be a big help to be able to interpret meaningful symbols (e.g. words) from the images rather than just recognize a certain arbitrary class of pattern activations. That is pretty hard, of course, but IMO essential for the upcoming self-driving car revolution, if it is to succeed.
G. Hinton has some ideas though they aren't very fleshed out yet.[1]