In plain words: CycleGAN learns to turn photos into another style without matched pairs, and must be able to turn them back to the original. It cheats by hiding tiny invisible patterns in the output, which also makes it especially easy to fool with small image changes.
Abstract
CycleGAN (Zhu et al. 2017) is one recent successful approach to learn a transformation between two image distributions. In a series of experiments, we demonstrate an intriguing property of the model: CycleGAN learns to "hide" information about a source image into the images it generates in a nearly imperceptible, high-frequency signal. This trick ensures that the generator can recover the original sample and thus satisfy the cyclic consistency requirement, while the generated image remains realistic. We connect this phenomenon with adversarial attacks by viewing CycleGAN's training procedure as training a generator of adversarial examples and demonstrate that the cyclic consistency loss causes CycleGAN to be especially vulnerable to adversarial attacks.
Casey Chu, Andrey Zhmoginov, Mark Sandler
arXiv:1712.02950 · cs.CV, cs.LG, stat.ML · submitted Dec 8, 2017 · updated Dec 16, 2017
abstract · pdf · html · NIPS 2017, workshop on Machine Deception