Adversarial image attacks are no joke
91–100 of 196 posts
Re: Adversarial image attacks are no joke
#92Earlier quoted context omitted.
I bet I could cause a significant fraction of human vision systems to get in a crash with a well placed sticker. I'd replace " ".
I'm pretty sure this would fail to kill people on almost every place you could try it. And if it works somewhere, it's because there are other problems with the road that should be fixed. Human driving is full of redundancies, and there is a clear hierarchy of information. People will not rush into a road full of cars going on the other way, it doesn't matter what the signs say. If your automated driving system doesn…
Re: Adversarial image attacks are no joke
#93As somebody who works on computer vision, my general take on these things is that adversarial examples are like poison. It would be fairly easy to add poison to a water supply or the air intake of a large building and kill a large number of people. This rarely happens though. It's ok that water sources, buildings, and people aren't completely immune to poison. The safety requirement isn't that poison can't hurt. Inst…
Re: Adversarial image attacks are no joke
#94As somebody who works on computer vision, my general take on these things is that adversarial examples are like poison. It would be fairly easy to add poison to a water supply or the air intake of a large building and kill a large number of people. This rarely happens though. It's ok that water sources, buildings, and people aren't completely immune to poison. The safety requirement isn't that poison can't hurt. Inst…
Re: Adversarial image attacks are no joke
#95Earlier quoted context omitted.
> For example, consider the case of pasting a sticker on a speed limit sign that causes Teslas to swerve off the road. If your vision system can be caused to swerve off a road by a sticker then maybe it shouldn't be used?
I bet I could cause a significant fraction of human vision systems to get in a crash with a well placed sticker. I'd replace " ".
If I write crappy paint program and all I can claim is, "It's no worse than the time/effort of drawing by hand," what exactly have I achieved in your opinion?
And if the posts on HN wrt blockchain and ML constantly feature these "no-worse-than-what-we-are-replacing" arguments while posts about, say, paint programs don't, what does that say about the buzz around blockchain and ML?
Edit: clarification
Re: Adversarial image attacks are no joke
#96Is traditional computer vision less susceptible to these? Since the features are human crafted, it sounds to me that the risk would be much lower.
Re: Adversarial image attacks are no joke
#97As somebody who works on computer vision, my general take on these things is that adversarial examples are like poison. It would be fairly easy to add poison to a water supply or the air intake of a large building and kill a large number of people. This rarely happens though. It's ok that water sources, buildings, and people aren't completely immune to poison. The safety requirement isn't that poison can't hurt. Inst…
Doing things with intent to harm others is illegal, even if you use a sticker to do it.
> Tesla should be civilly liable for cases where preventing such an incident was possible with known technology.
This is currently likely the case, but is not proven until a lawsuit happens.
Re: Adversarial image attacks are no joke
#98Earlier quoted context omitted.
1 and 2 are almost always going to be impossible in the US due to the first amendment (this is a feature not a bug) 3 doesn't seem crazy, but it would practically end up with caps, which might not be what you're looking for 4 This both: seems possible, and will basically never happen due to cost in every little jurisdiction
#1 is certainly not a first amendment violation. In fact, the supreme court still holds that certain restrictions on billboards are allowed even for the purpose of preserving beauty. Safety is a much more compelling interest than beauty, so I don't expect states and cities will lose their ability to regulate road signage. See Metromedia, Inc. v. San Diego for example. #2 is expensive and difficult, but that's what we…
If I wanted to print an image and put it on a t-shirt that would trick a computer driven car into doing something if its cameras saw my shirt, that’s not my problem. The barrier to entry is much lower too so I think it’s up to the engineers to solve it instead of trying to dump the hard problems on society.
Re: Adversarial image attacks are no joke
#99As somebody who works on computer vision, my general take on these things is that adversarial examples are like poison. It would be fairly easy to add poison to a water supply or the air intake of a large building and kill a large number of people. This rarely happens though. It's ok that water sources, buildings, and people aren't completely immune to poison. The safety requirement isn't that poison can't hurt. Inst…
That worked super well with DVD CSS right? Let’s face it, people are going to print adversarial images on t-shirts.
And if they actually do hurt someone, I imagine they would be criminally liable.
Re: Adversarial image attacks are no joke
#100Earlier quoted context omitted.
> It gives the illusion of security, but they would absolutely not deter a determined threat actor. Sure. And the threat of jail/imprisonment doesn't deter determined murderer's. It doesn't mean we shouldn't put deterrents.
>It doesn't mean we shouldn't put deterrents. GP doesn't say we shouldn't, but rather that it's not good enough.