Live data from Hacker News

Adversarial design printed on a shirt to fool object recognition algorithms

vice.com

11–20 of 76 posts

Re: Adversarial design printed on a shirt to fool object recognition algorithms

#12
post #3

Lovely. A bit of social proof hacking could go a long way to making these kind of adversarial designs more common on the streets - hire some actors to go round the city with CV-defeating makeup on, or these T-shirts, or these garments: https://www.vice.com/en_ca/article/qvgpvv/adversarial-fashio... (though I wonder if those designs might be shut down by copyrights on license plate designs?) (As an aside I got a kick…

Don't forget to have them carry around 3D printed full auto assault turtles.

Re: Adversarial design printed on a shirt to fool object recognition algorithms

#13
Reminds me of the "hack" that was done to the Samaritan system in the excellent TV series "Person of Interest." Granted, you have to suspend disbelief on many points of AI to enjoy that show but I never understood why they couldn't work around the bug that was placed in the system that prevented the identification of seven people. In the examples cited, like tricking the AI into thinking that a turtle was a gun, there's an easy fix once the misclassification is noticed. I suspect the "t-shirt of invisibility" will similarly be accounted for in the system and that people seen wearing it will be targeted for MORE scrutiny as it could be presumed they are trying to hide in plain sight and that there might be a nefarious reason for it.

Re: Adversarial design printed on a shirt to fool object recognition algorithms

#15
post #13

Reminds me of the "hack" that was done to the Samaritan system in the excellent TV series "Person of Interest." Granted, you have to suspend disbelief on many points of AI to enjoy that show but I never understood why they couldn't work around the bug that was placed in the system that prevented the identification of seven people. In the examples cited, like tricking the AI into thinking that a turtle was a gun, ther…

> they couldn't work around the bug that was placed in the system that prevented the identification of seven people

The explanation given was that one server per person would invalidate some portion of the overall profile so the identity would be misclassified (for all main characters)

Re: Adversarial design printed on a shirt to fool object recognition algorithms

#17
post #7

I have always wondered what the minimum amount of makeup needed to be "invisible" to facial recognition would be. In some cyberpunk future I could see people breaking up their features with thin black lines or something to fool cameras.

What you're looking for is CV dazzle or dazzle makeup. Check out https://en.wikipedia.org/wiki/Computer_vision_dazzle and some more practical (?) information at https://cvdazzle.com/

Do these still work? I expect designs like this to age quickly. Try reverse-image-searching them :)

Re: Adversarial design printed on a shirt to fool object recognition algorithms

#20

Colour me skeptical. There are multiple ways to capture features and the shirt may fool one set of algorithms but I highly doubt they'll fool them all.

Like any good security protocol, this wouldn't be the only line of defense. A combination of adversarial clothing, makeup, hair style, and accessories would be used. And constantly evolving, making countermeasures harder. Security is always reactionary, you can't defend against an attack you've never seen before.
Post reply on HN