In plain words: Small image tweaks designed to fool one vision model were adjusted to match early human vision and shown briefly to people. The tweaks that fooled many other models also shifted what time-limited viewers chose, showing humans can be misled the same way.
Abstract · Adversarial Examples that Fool both Computer Vision and Time-Limited Humans
Machine learning models are vulnerable to adversarial examples: small changes to images can cause computer vision models to make mistakes such as identifying a school bus as an ostrich. However, it is still an open question whether humans are prone to similar mistakes. Here, we address this question by leveraging recent techniques that transfer adversarial examples from computer vision models with known parameters and architecture to other models with unknown parameters and architecture, and by matching the initial processing of the human visual system. We find that adversarial examples that strongly transfer across computer vision models influence the classifications made by time-limited human observers.
Gamaleldin F. Elsayed, Shreya Shankar, Brian Cheung, Nicolas Papernot, Alex Kurakin, Ian Goodfellow, Jascha Sohl-Dickstein
arXiv:1802.08195 · cs.LG, cs.CV, q-bio.NC, stat.ML · submitted Feb 22, 2018 · updated May 22, 2018
abstract · pdf · html
I opened the paper hoping to see some examples of images that look to me like one thing on first glance, and something else on closer inspection. The best image is the one with the spider on a blurred-snake background, and that's not going to trick anyone who looks at it for more than a second.
The humans were shown each image for either 63ms or 71ms. That's 1-2 frames of a movie. So whilst the result is important, it's not as surprising as you might expect.