Researchers reveal patterns than can 'blind' an AI
According to the researchers, the experiment shows how'fragile' current approaches are, as the exploit relies on barely perceptible'noise' to remove only a particular group from the image, making the attack far less obvious even to humans'If an adversary's objective is to remove all occurrences of a specific class (e.g. an adversary trying to hide all pedestrians to deceive an emergency braking system) then the attack is maximally inconspicuous if it leaves the prediction for all other classes unchanged and only hides the target class,' the authors explain. In their experiment, the researchers applied the universal adversarial perturbations to images in Cityscapes, a dataset that contains 3,475 images from 44 different cities. By doing this, they were able to remove nearly all pedestrian pixels – and, the background remained mostly unchanged. Such an attack would mean that pedestrians would be invisible to a self-driving car.
Apr-25-2017, 00:53:15 GMT
- Country:
- North America > United States
- Massachusetts (0.05)
- Europe > Germany
- Baden-Württemberg > Freiburg (0.05)
- North America > United States
- Genre:
- Research Report > New Finding (0.75)
- Industry:
- Technology: