https://news.ycombinator.com/item?id=46364338
https://news.ycombinator.com/item?id=35224219
We’ve seen this arms race before and know who wins. It’s all snake oil imo
https://news.ycombinator.com/item?id=46364338
https://news.ycombinator.com/item?id=35224219
We’ve seen this arms race before and know who wins. It’s all snake oil imo
I haven't and I don't know who wins. Who wins?
Adversarial examples aren't snake oil, if that's what you meant. There's a rich literature on both producing and bypassing them that has accumulated over the years, but while I haven't kept abreast with it, my recollection is that the bottom line is like that for online security: there's never a good reason not to make sure your system is up to date and protected from attacks, even if there exist attacks that can bypass any defense.
Where in this case attack and defense can both describe what artists want to do with their work.
I could imagine you could make one that was effective against multiple recognizers, but not in general.
I'd also guess it'd be easy to get rid of this vulnerability on the model side.
Don't confuse attempting to make AI misclassify an image as a security measure.
And yes, this is snake oil and the AI wins every time.
At the end of the day a human has to be able to interpret the image, and I'd add another constraint of not thinking it looks ugly. This puts a very hard floor on what a poisoner can put in an image before the human gets sick. In a rapid turn around GAN you hit that noise floor really quickly.
It's kinda funny in a way because effectively they're helping iron out ways in which these models "see" differently to humans. Every escalation will in the end just help make the models more robust...
That they are disclosing the tools rather than e.g. creating a network service makes this even easier.
It's all to benefit industry, whether the academics realize it or not.
In fact I would say the opposite is true. LLMs must protect against this as a security measure in unified models or things the LLM 'sees' may be faked.
If for example someone could trick you into seeing a $1 bill as a $10 it would be considered a huge failure on your part and it would be trained out of you if you wanted to remain employed.
Never mind that the more people try to corrupt a model, the more likely that future models will catch these corruption attempts as security and trust/safety issues to fix and work around.
The next Nightshade will eventually be viewed as malware to a model and then worked around, reconstructing around the attempt to break a model.
This is just grandstanding. Half the people from this lab will go on to work for AI companies.
175 years of history would disagree with you: https://en.wikipedia.org/wiki/Security_through_obscurity