Hacker News new | ask | show | jobs
by abidlabs 2667 days ago
As one of the authors of the "Interpretation of Neural Networks is Fragile" paper, I would agree with you.

To a certain extent, saliency maps can be perturbed even with random noise, but the more dramatic attacks (and certainly the targeted attacks, in which we move the saliency map from one region of the image to a specified another region of the image) require carefully-crafted adversarial perturbations.