Live data from Hacker News

Hacking the Brain with Adversarial Images

spectrum.ieee.org

11–20 of 32 posts

Re: Hacking the Brain with Adversarial Images

#11
post #7
post #5

So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.

The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…

It’s not the same. Shining lasers into eyes is not scalable. However, placing a little sign at the side of a road that causes self driving vehicles to swerve out and crash violently, killing the occupants, can be done in mass.

Re: Hacking the Brain with Adversarial Images

#12
The subsequent images and conclusion that adverserial attacks against multiple models would be effective against humans seems tautological. Individual models may be unique, but multiple models are related in that -human- classifiers are the final source of truth. Anything that works against all of them is indirectly targeting the human classifiers that unite them.

Re: Hacking the Brain with Adversarial Images

#13
post #7

Earlier quoted context omitted.

The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…

It’s not the same. Shining lasers into eyes is not scalable. However, placing a little sign at the side of a road that causes self driving vehicles to swerve out and crash violently, killing the occupants, can be done in mass.

If you make the sign red and octagonal you could even kill human drivers too! Or maybe if you slapped an illusory-motion pattern over something that looked like a dog, then people might swerve into the opposite lane to avoid it, double kill! Shock, horror!

Human vision is slightly more robust solely because it's had more time to go back and forth with adversaries. Nothing prevents ML from reaching the same levels of safety. Nothing prevents you from deploying attacks against humans that're identical to to the attacks against artificial systems.

Re: Hacking the Brain with Adversarial Images

#14
post #7

Earlier quoted context omitted.

The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…

It’s not the same. Shining lasers into eyes is not scalable. However, placing a little sign at the side of a road that causes self driving vehicles to swerve out and crash violently, killing the occupants, can be done in mass.

Further, laser beaming eyes isn't an intellectual pursuit; entering an arms race with some of the world's top engineers certainly is.

I imagine most self-driving car hackers will react to any successes with "holy shit it worked" followed by remorse.

Re: Hacking the Brain with Adversarial Images

#15
post #7
post #5

So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.

The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…

The argument that there exists SOME mask which will transform a cat into a dog for humans and computers is not relevant to the discussion. The anatomical features of the face in this picture have changed. The reason adversarial attacks against ML are scary is very simply that you can accomplish them robustly in ways that humans won't detect simply by looking at the images.

Obviously I can manipulate a picture of a cat to make it look like a dog.

Re: Hacking the Brain with Adversarial Images

#16
post #8

Article subheading: > Researchers from Google Brain show that adversarial images can trick both humans and computers, and the implications are scary So the IEEE is telling me how to feel about this article in addition to presenting the facts. One might even consider that "hacking the brain with adversarial text". :-) > A worrying possibility is that supernormal stimuli designed to influence human behavior or emotions…

Exactly like clickbait headlines, political posturing, advertising, and propaganda - all of which are misleading stimuli designed to elicit a specific behavioural and cognitive response.

Brains are very easy to hack. The idea that we're reliable exemplars of rational objectivity and rigorous self-awareness is nonsense.

Re: Hacking the Brain with Adversarial Images

#17
post #7
post #5

So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.

The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…

> The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML

That may be the point, but it's not proven by this study. Cats and dogs have many structural similarities, as do the other adversarial examples (panda / gibbon, cabbage / broccoli). We know that this isn't just an artefact of the human visual system because we know they are very similar in non-visual ways too, i.e. they are genetically and behaviourally similar (compared with random other items in the world, such as bananas and toasters).

This study's choice of images seems to acknowledge that when the human visual system makes mistakes, it does so in a far more robust way than ML-generated models do. Even the fact that this effect is robust across many individuals, versus adversarial ML images being model-specific, demonstrates this. Mistaking a cat for a dog, given a 50ms window, is much less likely to be disadvantageous to us than mistaking a cat for a computer, or a banana for a toaster.

In other words, this study is a long way away from demonstrating that applying a bit of static to an image could make us mistake a car for a tree, whereas in an ML scenario such a mistake seems quite plausible.

Re: Hacking the Brain with Adversarial Images

#18
post #3

This reminds me strongly of the BLIT series of short stories, in which a category of images is discovered that cause processing problems ‘glitches’ in the human brain with fatal results. http://www.infinityplus.co.uk/stories/blit.htm That’s the first one, others are available online too.

The other work of popular fiction that gets referenced in these cases is, of course, Snow Crash.

Re: Hacking the Brain with Adversarial Images

#19
This is interesting. Could this be a way to watermark images automatically before uploading to the "cloud" to prevent AI processing by large corporations (e.g. Facebook)? Main problem seems that the AI can be adjusted down the road to eventually fix it.

Re: Hacking the Brain with Adversarial Images

#20
How far fetched would it be to assume that in the future, facebook would start building a neural network for each of its users, training it to like the same content as you ? With the amount of data generated by the endless scrolling, you could build a fairly accurate neural network of which content produce which emotion, and then generate adversarial images for targeted advertising.
Post reply on HN