Hacker News new | ask | show | jobs
by bigiain 2151 days ago
I think there's a (hopefully strongly privacy preserving) combinatorial explosion here though. If current models can be trained to accurately-enough recognise me with, say, 100 training images - this tool might produce unique enough perturbations to require 100 images for each of the possible perturbations, potentially requiring you to train your new model using tens of thousands or millions of cloaked versions of the 100 images for each of the targets in your training set.

(If I were these researchers I'd totally be reaching out to AWS/Azure/GCE for additional research funding... <smirk>)