Psychedelic stickers that interfere with AI image recognition
techcrunch.com
techcrunch.com
One can paste such a sticker on top of the face or other objects to be disguised and it might reduce recognition accuracy a bit, but applying some “paint-in” algorithms to fill in the blank covered by the sticker would basically remove its effect. That is unless it is used to cover some prominent features, although that is often unpractical in many circumstances.
If you think you can write a better image classifier by first segmenting the image before using ML, then I encourage you to get your own computer vision paper published and see how that works for you.
1. They look for the general shape of the face
2. They look for a skin region and classify it based on shape.
From the segment, then it becomes a complex search problem to match the face to a known face.
Unfortunately this will make you stand out like a Christmas tree on the video. But this must cripple automated facial recognition technology.
[0]: http://odditymall.com/justice-caps-hide-your-face-from-surve...
If necessary, next week these system can learn to ignore these.
Also in the article, they test a detector that has to identify a single object in an image that contains two: place an actual toaster next to the banana and call it fooled.
More than that, you can fool models that work completely differently (like decision trees, SVM and kNN) with false data made for the other model, which shows some kind of underlying similarity in there that we don't know yet.
Or maybe just similarity of the training sets?
Humans would consider this a non-interesting exploit.
This detector has to choose a label for an image with two labels. Use something like YOLO2 on this, and the detector will recognize a banana AND a toaster.
Now we do know that compared to humans, these detectors over-react to textures over structure. If you look at the sticker, you can see how it kinda looks like a toaster: the big red blob looks a bit like a toaster button. A generic shape is there, the thing over the button looks like both the control to lower the toasts and the slit where the toasts are.
These classifiers will get better at recognizing structure, especially if we train them against this kind of things.
I guess we'll see people sticking these on their faces?
https://www.csail.mit.edu/news/fooling-googles-image-recogni...
PS -- NIPS is in Long Beach now? What a shame.
Back then, spammers sent deliberately gibberish messages. The goal was that users (rightfully) marked those as SPAM, somehow disturbing the machine learning and thus weakening the overall SPAM recognition.
Alas, I don't know if this was actually working, and if so, how large the effect was. This would be an interesting bit of history.
Oily legs illusion https://i.imgur.com/14U9rqn.jpg