Lovely. A bit of social proof hacking could go a long way to making these kind of adversarial designs more common on the streets - hire some actors to go round the city with CV-defeating makeup on, or these T-shirts, or these garments: https://www.vice.com/en_ca/article/qvgpvv/adversarial-fashio... (though I wonder if those designs might be shut down by copyrights on license plate designs?) (As an aside I got a kick…
Adversarial design printed on a shirt to fool object recognition algorithms
21–30 of 76 posts
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#22Colour me skeptical. There are multiple ways to capture features and the shirt may fool one set of algorithms but I highly doubt they'll fool them all.
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#23Colour me skeptical. There are multiple ways to capture features and the shirt may fool one set of algorithms but I highly doubt they'll fool them all.
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#24Re: Adversarial design printed on a shirt to fool object recognition algorithms
#25Colour me skeptical. There are multiple ways to capture features and the shirt may fool one set of algorithms but I highly doubt they'll fool them all.
Like any good security protocol, this wouldn't be the only line of defense. A combination of adversarial clothing, makeup, hair style, and accessories would be used. And constantly evolving, making countermeasures harder. Security is always reactionary, you can't defend against an attack you've never seen before.
Yes you can, that's part of the appeal of applying machine learning to security. They don't rely on things like signatures or existing heuristics to identify things as malicious.
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#26Colour me skeptical. There are multiple ways to capture features and the shirt may fool one set of algorithms but I highly doubt they'll fool them all.
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#27Earlier quoted context omitted.
Like any good security protocol, this wouldn't be the only line of defense. A combination of adversarial clothing, makeup, hair style, and accessories would be used. And constantly evolving, making countermeasures harder. Security is always reactionary, you can't defend against an attack you've never seen before.
> Security is always reactionary, you can't defend against an attack you've never seen before Yes you can, that's part of the appeal of applying machine learning to security. They don't rely on things like signatures or existing heuristics to identify things as malicious.
Think of it like your body. It learns to identify viruses. Does that mean you're immune from novel viruses or new strains of the flu?
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#28It's also then super easy to say that the individual wearing the shirt is likely to try to usurp monitoring. In practice this type of thing will likely make you a more prevalent target for monitoring along the lines of "what do you have to hide?".
Not that I agree at all with large-scale monitoring or think anyone should prove that they don't have something to hide. Only that it paints the target on your back.
Re: Adversarial design printed on a shirt to fool object recognition algorithms
#29Re: Adversarial design printed on a shirt to fool object recognition algorithms
#30We need better deployed testing suites that can test an adversarial model against many popular classifiers, not just 2.
Even so, the paper itsef shows tht their tshirt doesn't make the wearer undetectable, only partially-undetectable. A security system won't ignore you just because it only saw you 10% of the time you were present (unless it's an Uber self-driving car).