Inverting facial recognition models
blog.floydhub.com
blog.floydhub.com
Something that came to mind as a potential way to get clearer and more realistic results is to add GAN loss. You can reference this as an example (shows pretraining on L2/mse and after with GAN):
https://github.com/fastai/course-v3/blob/master/nbs/dl1/less...
I'm not 100% sure if it'd work but it seems like a potentially cool followup project.
For image tasks I read that adding more layers to the model helps find more complicated features of the images, i.e. first layer identifies edges, next layer finer outlines and so on. Would adding more layers in this model mean you need less epochs to make it more accurate or would there be any trade off like that?
Since the question is about training speed though, in general, larger models require more data which requires more time to train, so you'd actually increase both your data requirements, and time required to train.
1. I'm curious about biometrics security systems generally (e.g., fingerprint scanners). Are there biometrics indicators that are actually secure, or can everything that's scanned be copied and leaked?
2. Is Irhum really a jr. in high school?? Wow.
If you want an exact match, like in storing passwords, all you need is to store a hash and throw the original away (and there's certainly more nuances to this, like salting, but the rough idea is this). When a user enters a password, run it through a hash function and see if the hashes match.
This isn't the case for similarity matching, which most face recognition systems use. You need to store the actual embedding, and not the hash, because two face embeddings of even the same person are unlikely to ever be exactly the same, just "close". If you hash even two nearby inputs, any standard hash function will map them as far apart as possible, destroying any sense of distance you'd have to compute the similarity between the stored embedding and the query embedding.
This extends to any method whose internal representations are designed to function based on similarity matches; you need to store the original.
2. Last time I checked, yeah :)
I.e. could an average american adult with reasonable People-magazine-based knowledge paint these celebrities as well with nothing but their names as input? Is it even the same task?
All deep learning model outputs are by design differentiable, and anyone with access to the full output of your model can potentially reverse engineer it using model distillation.
If you're running a cloud service, it's pretty easy, just make sure your API sends back processed inputs.
If it's on device, things become a bit more involved, but ideally, the embeddings should be stored as encrypted files (and not directly loadable matrices), and only readable by a small part of your overall program, which sends back the name of the person after performing similarity match, to other parts of the program. Your entire program should not have access to the embedding.
I was pleasantly surprised that you are 11th grade! What other projects are you working on?
I'm currently working on applications in road safety, and have also recently taken up an interest in learning about interpretability and fairness in machine learning models (for instance, I really loved this paper: https://arxiv.org/abs/1711.11279 and am working on making an easily accessible implementation of it).
Another thing that caught my attention is how deep learning is being used to build new developer tools, such as models that read code and automatically generate comments.
There's just so much ground to cover, simply because deep learning is such a versatile, universally applicable method.