So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.
The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…
Hacking the Brain with Adversarial Images
11–20 of 32 posts
Re: Hacking the Brain with Adversarial Images
#12Re: Hacking the Brain with Adversarial Images
#13Earlier quoted context omitted.
The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…
It’s not the same. Shining lasers into eyes is not scalable. However, placing a little sign at the side of a road that causes self driving vehicles to swerve out and crash violently, killing the occupants, can be done in mass.
Human vision is slightly more robust solely because it's had more time to go back and forth with adversaries. Nothing prevents ML from reaching the same levels of safety. Nothing prevents you from deploying attacks against humans that're identical to to the attacks against artificial systems.
Re: Hacking the Brain with Adversarial Images
#14Earlier quoted context omitted.
The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…
It’s not the same. Shining lasers into eyes is not scalable. However, placing a little sign at the side of a road that causes self driving vehicles to swerve out and crash violently, killing the occupants, can be done in mass.
I imagine most self-driving car hackers will react to any successes with "holy shit it worked" followed by remorse.
Re: Hacking the Brain with Adversarial Images
#15So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.
The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…
Obviously I can manipulate a picture of a cat to make it look like a dog.
Re: Hacking the Brain with Adversarial Images
#16Article subheading: > Researchers from Google Brain show that adversarial images can trick both humans and computers, and the implications are scary So the IEEE is telling me how to feel about this article in addition to presenting the facts. One might even consider that "hacking the brain with adversarial text". :-) > A worrying possibility is that supernormal stimuli designed to influence human behavior or emotions…
Brains are very easy to hack. The idea that we're reliable exemplars of rational objectivity and rigorous self-awareness is nonsense.
Re: Hacking the Brain with Adversarial Images
#17So if I make a cat look like a dog, people think it's a dog. That's amazing and totally unexpected.
The point is that the human brain is just as vulnerable to the adversarial attacks that people are claiming will be the downfall of ML. It's like the people that scream about people shining lasers into the cameras of autonomous vehicles - yeah, sure, if you did the same thing to a human driver you'd get exactly the same crash, why are you suddenly worried about this? And it's more than just "making it look like a dog…
That may be the point, but it's not proven by this study. Cats and dogs have many structural similarities, as do the other adversarial examples (panda / gibbon, cabbage / broccoli). We know that this isn't just an artefact of the human visual system because we know they are very similar in non-visual ways too, i.e. they are genetically and behaviourally similar (compared with random other items in the world, such as bananas and toasters).
This study's choice of images seems to acknowledge that when the human visual system makes mistakes, it does so in a far more robust way than ML-generated models do. Even the fact that this effect is robust across many individuals, versus adversarial ML images being model-specific, demonstrates this. Mistaking a cat for a dog, given a 50ms window, is much less likely to be disadvantageous to us than mistaking a cat for a computer, or a banana for a toaster.
In other words, this study is a long way away from demonstrating that applying a bit of static to an image could make us mistake a car for a tree, whereas in an ML scenario such a mistake seems quite plausible.
Re: Hacking the Brain with Adversarial Images
#18This reminds me strongly of the BLIT series of short stories, in which a category of images is discovered that cause processing problems ‘glitches’ in the human brain with fatal results. http://www.infinityplus.co.uk/stories/blit.htm That’s the first one, others are available online too.