Hacker News new | ask | show | jobs
by nullc 3263 days ago
Though I generally agree with your point, the tree vs stopsign example may not be the best because it would arguably work equally well on humans.
2 comments

Did the perturbed image of the cat in the article look like a desktop computer to you?

The point is that humans would see one thing whereas computers would be highly confident it is something else.

Only if the adversarial image printed doesn't look like the stop sign, though the example in this article shows that it's entirely possible to make an image that just looks like a distorted/badly-printed kitten to a human but completely different to a computer. A similar image for a stop sign might just look like wear in the paint or weird reflections or something but still look like a stop sign to a human.
yes but wont we still notice that self driving cars aren't stopping at the stop sign? and we'd investigate