Breaking Linear Classifiers on ImageNet
karpathy.github.io
karpathy.github.io
Convolutional Boltzmann machines have been developed, and neural networks trained with Backpropagation can be pre-trained with generative models. Would this help alleviate the problem?
I ended up with a ~98% accurate Gaussian kernel SVM classifier and my generated images all looked like numbers.
I also got ~96% using KNN, but haven't figured out how I would measure confidence in such a classifier (average distance?)
Any ideas?
Its hard to say if a similar hack would work on people since we can't easily run an high speed optimization over the human visual cortex. Maybe some mice?
If you haven't seen this picture before: http://www.moillusions.com/wp-content/uploads/photos1.blogge... it should appear as meaningless noise. After you spot the Dalmation dog, you will notice it in the future.
Also.. In the "incomprehensible noise" pattern classes, I can pretty clearly see features that I would identify as a robin, cheetah, armadillo, and lesser panda. I don't think this means the classifiers are being fooled, they are just not being trained to recognize the class of "noisy image that looks kind of like something but is actally noise"
It may become an attack vector, but one the is very difficult to fit to the classifier you are targeting (your car may be using online learning, so there is a chance that an image generated on one self driving car won't work on another of the same model) then you have to show this carefully generated image to the car, but if you show it to the camera, it will already be distorted beyond its fooling capability. due to angle, lighting, lenses etc.