|
|
|
|
|
by dontreact
2779 days ago
|
|
I don’t see how you can make any claim about “most human adversarial examples”. There is a huge space of images and we have explored a negligible part of it. Also a) and b) empirically seem to be true of the test sets people have collected thus far of the natural world for these models. In short, we have no evidence that adversarial examples of the type being studied occur commonly in images collected by self driving cars. |
|
You hypothesize that there are comparable examples for humans somewhere out there in the domain of all possible images, but the fact that, for all the countless cases of people looking at things that have occurred in humanity's existence, no-one has found a good example, suggests that, from the pragmatic point of view that you propose, image-recognition software has some catching-up to do.
Maybe a system that seeks consensus among several differently-trained models would be more robust.