Robust adversarial inputs
OpenAI Blog
Researchers created images that consistently deceive neural network classifiers across different scales and viewing angles. The images remain effective at fooling the networks despite variation in perspective, directly contradicting prior assertions that multi-scale image capture would protect autonomous vehicles from adversarial attacks. This finding suggests that defensive strategies relying on multiple viewpoints do not adequately protect against carefully constructed adversarial inputs.
Why it matters
We’ve created images that reliably fool neural network classifiers when viewed from varied scales and perspectives. This challenges a claim from last week that self-driving cars would be hard to trick maliciously since they capture images from multiple scales, angles, perspectives, and the like.