Live data from Hacker News

Images altered to trick machine vision can influence humans too

deepmind.google

51–60 of 86 posts

Re: Images altered to trick machine vision can influence humans too

#51
post #32
post #23

"In our example, we may see a vase of flowers, but some activity in the brain informs us there’s a hint of cat about it." IMHO this is not the same as computer vision thinking a rolled over school bus is a snow plow. This is asking if someone sees an elephant or a unicorn in a cloud. Asking if a picture of a stop light at an intersection is "cat like" seems to be pretty suspectable to over fitting. Rorschach inkblot…

To me that evokes a dimension of disbelief, or suspicion that the data is wrong, separate from what it does or doesn't resemble. Consider the difference between a human stating "that's an impossible nonsense picture, but if had to describe it then it's a half-Cat and half-Truck abomination" compared to a computer yielding " There is a 50% chance that is a Truck, and a 50% chance that is a Cat."

It might not be clear from the article, it took me a bit of scanning back and double checking myself: the impossible nonsense picture is _overlaid_ on the left hand picture to produce the right hand picture

which is, at least to our conscious verbalizing mind, ~indistinguishable from the left hand picture. the interesting part is they _are_ distinguishable.

as you point out, you'd expect a human to just be like "uhhhh...either?", but it turns out we do see something subconciously, because people do identify the overlaid image at > chance

Re: Images altered to trick machine vision can influence humans too

#52

Earlier quoted context omitted.

I think you misunderstand the experiment. They take an image of the flower, they perturb it so that the neural network classifies it as a "cat". They take another copy, perturb it so that the neural network classifies it as a "truck". They ask the subjects which one is more cat-like. A coin will choose the correct image 50% of the time. Likewise, a human that is not influenced by the pertubations will also pick corre…

Not clear if they had asked for "butterfly" instead of "cat" if 50/50 would have been the result. Similarly, if random perturbations influence choice, the baseline should include the noise from that.

I'm not really sure what you are commenting on. They tested this across multiple pairs of categories: (sheep, chair), (dog, bottle), (cat, truck), and (elephant, clock). This isn't a phenomena related to cats. The whole point of the study is to measure the impact of the noise. The "baseline" or control here would be to to not add noise to either of the two images and arbitrarily label one "cat" and the other "truck" and see how the humans perform. It is obvious that humans cannot do better than 50/50 and any deviation is purely chance. In the perfect world, you would do this control to ensure your experimental setup is not flawed in some other way but if the experiment was done as double blind then this control study would be pretty silly.

Re: Images altered to trick machine vision can influence humans too

#53

Caption on the first image : >when perturbed by a seemingly random pattern across the entire picture (middle), with the intensity magnified for illustrative purposes I don't understand? The pattern is not "seemingly random", it is "seemingly chosen to have subtle cat-features". One sees the ears at the top of them image and face-like features below. So, is it "we perturbed images to overlay cat-like features on a vis…

You're not wrong, but this is interesting insomuch as it's it's more from 100% bug on the bug-feature axis to...well, wetware has this bug too it's just subconcious.

But it's not a bug. You look at it and go “hey, those flowers look like a cat”, in the same way you go “that cloud looks like a horse” or “that tree looks like a face” (though, many people have specialised human face processing machinery in their visual systems, so this last example is potentially a little different). It's not a misclassification, just an awareness.

Re: Images altered to trick machine vision can influence humans too

#54
post #15

In case you were wondering what N was, their first experiment involved 16 undergrads psych students and the second experiment involved 12. https://link.springer.com/article/10.3758/BF03206939 Edit: I believe this linked survey is not the subject of the OP.

This comment is incorrect. For experiments 1 through 4, N was 38, 389, 396, and 389. The subjects were not undergrad psych students. The article linked in the parent comment does not correspond to any experiment in the blog post or the Nature Comms paper.

Here's the participants subsection in full for anyone that can't access the paper. Emphasis my own, made to help read

> __Experiment 1__ included 38 participants with normal or corrected vision. Participants gave informed consent and were awarded reasonable compensation for their time and effort. Participants were recruited from our institute but were not involved in any projects with the research team. __Experiment 1 control__ (i.e., Experiment SI-5) included 50 participants recruited from an online rating platform. For __Experiments 2–5__, we performed psychophysics experiments using an online rating platform. In each experimental condition, approximately 100 participants were recruited to participate in the task (see Supplementary Table 18 for the exact number). No statistical method was used to predetermine the number of participants, but the sample size was decided to be comparable to that used in previous similar studies. Participants received compensation in the range of $8–$15 per hour based on the expected difficulty of the task. No sex or age information was gathered from the participants for all our studies. Our participants were all located in North America and were financially compensated for their participation. __We excluded participants if__ they were not engaged in the task, as assessed using randomly placed catch trials with an unambiguous answer (e.g., pairing an unperturbed dog image with a cat image and asking which image is more cat-like). If a participant failed one catch trial for Experiments 2, 3, and 5, or two catch trials for Experiment 4, the task automatically terminated and their data was not analyzed.

Parent's numbers are specifically drawn from Figure 3 caption. (Some text may not format correctly. Apologies if I didn't catch)

> a Participants are shown two perturbations of the same image, of true class T, and are asked to select the image which is more like an instance of some adversarial class A. The image pair remains visible until a choice is made. b One of the two choices is an adversarial perturbation that increases the probability of classifying the image as A, denoted A↑. Experiment 2: T = A; the second image is perturbed to be less A-like, denoted A↓. Experiment 3: T ≠ A; the second image is formed by adding a right-left flipped version of the adversarial perturbation, which controls for the magnitude of the perturbation while removing the image-to-perturbation correspondence. Experiment 4: T ≠ A; the second image is an adversarial perturbation toward a third class , denoted . c We show examples of adversarial images which empirically yielded human responses consistent with those of the ANN (indicated by the red box) for ϵ = 2 and 16, corresponding to the lowest and largest perturbation magnitudes used in these experiments. Example images in (a–c) are obtained from the Microsoft COCO dataset62 and OpenImages dataset63; images in (a, b, and c) left are used for illustration outside of our stimulus set due to license limitations. d Box plots (same convention as Fig. 2c) quantifying participant bias toward A↑ (where A = T for Experiment 2 and A ≠ T for Experiments 3 and 4), as a function of ϵ for four different conditions (each a different adversarial class A) collected from n=389 participants for Experiment 2 (cat n = 100, dog n = 100, bird n = 90, bottle n = 99), n = 396 participants for Experiment 3 (cat n = 96, dog n = 100, bird n = 101, bottle n = 99) and n = 389 independent participants for Experiment 4 (sheep vs chair n = 97, dog vs bottle n = 99, cat vs truck n = 98, elephant vs clock n = 94). The red points (with ± 1 SE bars) indicate the mean across conditions. The black dashed line indicates the performance of a random strategy that is insensitive to the adversarial perturbations.

Re: Images altered to trick machine vision can influence humans too

#55
post #11

This is a poor bit of research. The question "is it more cat-like?" Is leading as it specifically instructs the participant to look for cat-like features. The experimenters neglect to establish the null hypothesis.

I also loved their filter

> We excluded participants if they were not engaged in the task, as assessed using randomly placed catch trials with an unambiguous answer (e.g., pairing an unperturbed dog image with a cat image and asking which image is more cat-like). If a participant failed one catch trial for Experiments 2, 3, and 5, or two catch trials for Experiment 4, the task automatically terminated and their data was not analyzed.

But I fully agree, the experiments are poorly setup and they don't even have inter-correlating analysis. It's hard to tell if a force is going on, which there very well might be.

Re: Images altered to trick machine vision can influence humans too

#56
post #49

Earlier quoted context omitted.

Am I the only one who finds this to be a sort of wasteful experiment for one of the supposed top research labs in the country to be publishing in such a (supposedly) prestigious journal? The findings aren't super shocking although they would be interesting enough if they had managed to collect a large enough sample. Instead they barely grasp at straws and come to an obviously inflated conclusion that neural nets and…

> findings aren't super shocking Aren’t they? Are you sure you understand what is the finding? > they would be interesting enough if they had managed to collect a large enough sample They did. The grand parent comment failed to read the right paper. > obviously inflated conclusion that neural nets and human brains are similar in some way But that is what they find. The human looks at two almost identical looking imag…

> Aren’t they? Are you sure you understand what is the finding?

Yeah, I got it.

> But that is what they find. The human looks at two almost identical looking images of flowers. And yet when they are asked which one is more cat like they pick the one which the neural network thinks is cat-like too.(Or at least they pick it more often than if they were just selecting randomly in this seemingly nonsense task.) That is exactly “similar in some way”. Similar in which image they find more cat-like. That is the similarity.

I'm saying the implication is that there is a not-yet-understood deeper connection illustrated by this discovery. I don't think they tested for that and I don't think it's hinted at. There are lots of reasons why this trick would work on both humans and neural nets that would amount to effectively no similarities in structure or process otherwise. That isn't to say it's not related somehow, just that their experiment simply shows the outcome is the same, but doesn't indicate why it's the same.

Having said all of that, you're definitely correct to imply I haven't read the full study. And I'm happy to admit my original comment contains misunderstandings. Sorry about that.

Re: Images altered to trick machine vision can influence humans too

#58
post #31
post #15

In case you were wondering what N was, their first experiment involved 16 undergrads psych students and the second experiment involved 12. https://link.springer.com/article/10.3758/BF03206939 Edit: I believe this linked survey is not the subject of the OP.

So when they say "more than half the time," they could very well be 9 and 7 people? No wonder they didn't cite the actual numbers in this summary write-up.

This result would be a lot more believable to me if I could take my own 20-30 question quiz and see how "good" I am at picking the "more X like" images. It seems like a missed opportunity for gathering more data, even if that data would be gathered in a less controlled setting.

Re: Images altered to trick machine vision can influence humans too

#59
post #58
post #31

Earlier quoted context omitted.

So when they say "more than half the time," they could very well be 9 and 7 people? No wonder they didn't cite the actual numbers in this summary write-up.

This result would be a lot more believable to me if I could take my own 20-30 question quiz and see how "good" I am at picking the "more X like" images. It seems like a missed opportunity for gathering more data, even if that data would be gathered in a less controlled setting.

Yeah, I was disappointed there wasn't example pairings with the result on another page or something just so I could give it a try! Every example is paired with info about how it was perturbed right next to it.

Re: Images altered to trick machine vision can influence humans too

#60

All examples (sheep vs chair, dog vs bottle, cat vs truck, elephant vs clock) are organic vs inorganic. Perhaps participants are reusing bouba/kiki[1] skills, evaluating whether the image looks organic (rounded) or inorganic (spiky) - and making their choice accordingly. [1]: https://en.wikipedia.org/wiki/Bouba/kiki_effect

I think they took a picture of a vase, and created two derivative images of the vase, one which was more cat-like and one which was more truck-like. In both cases, participants did better than average at guessing which one was the derivative image. In any case, I don't think this is explained by the bobo-kiki effect, since they were able to get the subjects to select both inorganic (truck) and organic (cat) derivatives of the same source image.
Post reply on HN