|
|
|
|
|
by toxik
1773 days ago
|
|
I think you're overestimating the capabilities of neural networks here, and especially ones that we know the exact weights for. It is fairly trivial to generate invisible noise that makes an input image get an entirely different hash. |
|
What I had in mind when referring to 'basic evasion' was 'cropping or rotating', as per your original comment.
All that being said, I admit that generating adversarial examples for models with known weights is not a difficult task.