Modelplace: AI Model Marketplace by OpenCV
modelplace.ai
modelplace.ai
I would urge everyone involved (OpenCV and people using the models) to not use this in any safety related application. The example given on the site is person detection for construction site safety. If you're going to use ML for something like this, hire someone with experience using it for such applications, that can understand the operating condition and failure modes. Your worksite is not safe if you just plugged in an online person detection model to a video feed.
Having a more standardized description, something like model cards [1] (CV example [2]) would be hugely beneficial IMO.
[1] https://arxiv.org/pdf/1810.03993.pdf
[2] https://drive.google.com/file/d/1f39lSzU5Oq-j_OXgS67KfN5wNso...
I wonder how feasible it would be to develop some formal ontology to describe the capabilities of models and attach them to model cards.
That could open up some interesting applications:
* automated search for a set of models to accomplish some task
* a human usable search engine for finding specific models
EDIT: to complete a sentence
Surely I could take a model, refine it slightly to get distinct weights (ie. not a flat clone) and unload it as my own novel variant?
...and I mean, is the problem not utterly fundamental?
When is a model “yours” or sell?
When you trained it? When you’re not using transfer learning? When you wrote the paper? When you own the training data? When you can recreate it from scratch?
I see this being problematic to look after...
That being said, if I am selling a bird classifier chances are that to train it I had to combine multiple datasets and someone can't easily finetune it to get better results.
The "attack" that you are describing could probably be mitigated by doing activation analysis. Given random initialization even with fine-tuning the activation distribution will be similar. Same method should be used to weed out people just repackaging the ImageNet pretrained model from torchvision.
That being said you can still distill a network into another with a teacher-student approach and that would be undetectable.
What authors could do is train the model on a dataset, but add a specific image that it flags as a key.
That way, if you keep the image private, you can check if a model is a clone of yours if recognises that specific image.
[1] https://mmpose.readthedocs.io/en/latest/modelzoo.html [2] https://mmpose.readthedocs.io/en/latest/topics/body(2d,kpt,i... [3] https://mmpose.readthedocs.io/en/latest/papers/algorithms.ht...
Worked fine on a VPN however (sorry, I know you probably don't like this).
After the account registration though, I did quite like trying out a couple models out on a couple frames of footage to see if the models would "work".
Tensorflow as an equivalent tool but I can't remember the name.
This looks deliberate because the Chief Scientist & President, Gary Bradski[1], created the OpenCV library that you refer to.[2]