How to hide from the AI surveillance state with a color printout
technologyreview.com
technologyreview.com
Another problem is that the minute that AI-proof clothing goes mass market is the minute it stops working (and for that reason, I suppose that you wouldn't want to have a product image, either.)
Will the book, "How To Make AI-proof Clothing" stop working the minute it is published, or will it teach generalizable skills.
It would seem unfair to pit a static object (prefab clothes) against a dynamic opponent (person detection AI). Better to compare two intelligent opponents.
What prevents GAN's from learning a new patch for them ?
That said, I think somebody could very easily come up with an adversarial makeup camouflage recommender. Imagine an interactive visualization of the regions of confidence of a facial recommendation system, hooked up to your webcam. You could have a visual overlay of where to apply make up to most damage the classifier's confidence of your identity.
It reminds me of the comic book The Private Eye by Brian K Vaughn. In that story the cloud "bursts" and online privacy evaporates overnight so everyone turns to intense camouflage to protect their identity. (https://en.wikipedia.org/wiki/The_Private_Eye)
Newer technology likely gets much better at spotting noses and eyes, but taking them entirely out of the picture probably helps. Also the asymmetry I can imagine helps a lot.
It's an awfully cool project, though; both artistic and a transformation-resilient adversarial input.
Does anyone know of any other such projects in the same vein?
At the very least, this could justify weird fashions in cyberpunk and other dystopian settings.
So they're better than us at some things, but can still fail dramatically at things that seem trivial to us.
I guess the solution could eventually be digital paint which rapidly and randomly alters itself, something akin to the scramble suits from A Scanner Darkly. https://www.dailymotion.com/video/xqrvzb
To really avoid image recognition, you need to create patterns that disrupt the actual patterns that these systems look for. For facial recognition, make your eyes and jawline hard to find, like Dazzle makeup does. To defeat full-body recognition systems, wear clothes with heavy patterns that make it hard to distinguish where your arms, legs and head are.
Even then, it's unlikely to work from all angles and against all backgrounds. You'd need something that adapts to the background you're likely to be seen against.
Basic image searches are looking for patterns so if you can have colors that break lines then you'd get the same effect. You would probably want to go with grey's and blue for city colors. Head to toe camouflage in the city puts you on the radar in other ways.
But the other trick about camouflage is to look like everyone else.
Hence why all soldiers dress the same out field and rank insignia is displayed in very mute colors on uniforms. This has the effect of hiding the officers in with the herd. Just don't be the guy holding the radio :P
Camo is all relative to the background. A gillie suit tailored for the local vegetation will fool literally every form of visible spectrum attempts at detecting the wearer (you need to look for heat or scent instead). It won't work very well at the mall though.
More seriously: I got the book How to Survive a Robot Uprising many years ago, and it has all sorts of tips like this one for defeating various parts of a robot's sensory and locomotion systems.
Dazzle works not to prevent detection of the shape/outline but to prevent any further information from being discerned (e.g. heading, precise shape and distance).
Depending on the kind of system you're trying to fool the former approach may be far easier.
I once saw a woman wearing black and white patterned leggings that perfectly replicated the intended effect of dazzle. I think that with clothing that isn't skin tight and therefore does not perfectly match the shape of one's body it would be even easier to pull off.
They have brightly patterned shells, and each one is different. One hypothesis for why this is is that it deprives the birds that eat them of a consistent pattern to look for.
Isn't this basically how camo defeats the human recognition system in our wetware?
Tesla will not pay anything: “he was deliberately hiding from cameras”.
(I still found the comment amusing!)
However, it may turn out to be a canvas of "art", who knows?
Many auto pilots, certainly Tesla's, work by using cameras. And, if you do fool cameras then the car might indeed kill you. Hell, they have a hard time keeping in the lane already - a couple of people have already died. Imagine what will happen if you fool it - OOPSE
And, if it goes to court, whoever has more expensive lawyer wins.
Also, just because someone's paranoid doesn't mean they're wrong.
The interesting thing is, for me: what if the printout is not made with the specific purpose of avoid recognition, just a a weird, colorful, hippie cloth and garments that AI struggle with.
We're a fashion engine and our system fully detected both of the people and all of their apparel (the person in question's shirt, his pants and it sees the "printout" as a low confidence handbag, as well as his shoes).
Not to say it would be impossible to trick our system, however, this method would not be sufficient given a good object hierarchy. Our system would have to have a triple miss across two methods - would need to miss his pants and his shirt and his body with the localizer, as well as his pants and shirt with the segmenter. And, if we were serious about detecting hiding people, you'd be surprised how gosh darn reliable the shoe detector portion is.
I don't see it being terribly feasible (and definitely not reliably so). Let's just say, it's not even close at all at this point. We miss zero of these things today.
https://www.youtube.com/watch?v=MIbFvK2S9g8
If a security camera uses this YOLO to identify people moving into the frame, then this important new development can help prevent security camera systems from making annoying sounds that would disturb the sleep of security guards.
If there is no "special sauce" and our brains are just very large neural networks that have what we see as intelligence is an emergent property would we be truly "thinking" by those standards?
We also suffer from adversarial patterns - they are called camouflage and optical illusions. Different from the ones that affect machines of course.
Walk through a city full of AI-powered facial recognition cameras holding a sign like this. Even if it works super well, you'll never know if it really does, or when an upgrade breaks your sign.
Real-time LCD display?
What would happen to a gorilla wearing the patch?
The soft used in the article is Yolo and I work a lot with it, and the results depends A LOT on the data you used for training. Some datasets will detect a gorilla as an human, some won't. Some even will detect two upside down fingers as a human.
So if you want your NN to not detect gorillas as a human, you have to include pictures containing gorillas where they are not labelled as humans.
I'd agree it's surprising, just that thinking about it you can see where it goes wrong. I imagine combining this with some kind of makeup to change the contours of one's face would work wonders.
I suppose it really depends on the training set. In some sense the set can be misleading. For instance if I have a load of pictures of people sitting by a table with their legs visible, that model might actually require a gap between your torso and your legs.
Instead, they provide cues that mess with the system's sense of scale, by having almost like a window into another, smaller scene, with vague, human-like images that the network presumably recognises as faces.
A group of tiny faces on the top of a single set of legs very much does not look like a human.
I don't really know much anything about this stuff or the cameras that might be used so forgive the noobness of this question, but I've been wondering - what about jamming? Thinking along the lines of super-bright IR (UV?) LEDs flashing in random sequences (i.e. around license plates).
"What’s that?" she asked.
"The ugliest T-shirt in the world," he said… "So ugly that digital cameras forget they’ve seen it."
Though I got the impression that it was a deliberate backdoor to allow security services to operate incognito, rather than an AI-fooling hack. Maybe just because the book was written before modern neural nets became so widespread.
A friend used to design systems for a major CCTV company. I asked him to add a similar backdoor for me, but sadly he never did...
Remember, the penultimate device in the novel was an antihero’s cornering the global marketplace order flow.
Radio waves never could read your thoughts or other crazy stuff so it would be less loony to see someone with a printed card than wearing a tinfoil hat.
Now, that doesn’t mean that a camouflage couldn’t be created that more generally avoids detection from these algorithms.