about
Synthesizing Robust Adversarial Examples (arxiv.org)
1 point by cdvonstinkpot on Nov 5, 2017 | hide | past | pdf | discuss on HN

In plain words: Trick images that fool AI usually break when photographed from a new angle or with camera noise. This method designs the trick across many such changes at once, and 3D-printed objects made this way fooled classifiers in the real world.

Abstract

Standard methods for generating adversarial examples for neural networks do not consistently fool neural network classifiers in the physical world due to a combination of viewpoint shifts, camera noise, and other natural transformations, limiting their relevance to real-world systems. We demonstrate the existence of robust 3D adversarial objects, and we present the first algorithm for synthesizing examples that are adversarial over a chosen distribution of transformations. We synthesize two-dimensional adversarial images that are robust to noise, distortion, and affine transformation. We apply our algorithm to complex three-dimensional objects, using 3D-printing to manufacture the first physical adversarial objects. Our results demonstrate the existence of 3D adversarial objects in the physical world.

Anish Athalye, Logan Engstrom, Andrew Ilyas, Kevin Kwok
arXiv:1707.07397 · cs.CV · submitted Jul 24, 2017 · updated Jun 7, 2018
abstract · pdf · html · ICML 2018

add comment on HN