Hacker News new | ask | show | jobs
by antpls 2324 days ago
Ctrl+f shows no mention of the study of post-processing quantization nor pruning on their tampered dataset.

Overall, I instinctively think that one can create an NN architecture that is not affected, or even easily detect the tampered pictures with a pre processing pass, and untamper them.

NN are actually fuzzy, they support noise, you could add a bit more noise in the dataset to defeat the "radioactiveness".

Also, I'm pretty sure Facebook is not doing it to protect user data, but I have no proof.

1 comments

but the noise FB adds is weighted a special way