Perhaps our perception shows robustness against adversarial examples simply because the world has always been adversarial during training. We never get a clean bitmap with a label, but coarse, disjointed, fragmentary, noisy samples from our retinas.
You rarely look at a picture of a car where someone changes a few pixels and you think it is an ostrich now. Most optical illusions are a tradeoff for learned biases that aid convergence on correct interpretations in the majority of circumstances.
-
-
Yeah, but judging “just a few pixels” is a subjective measurement. And arbitrary. There‘s occasions where a sufficiently well crafted image makes me think “nice car” where it turns out it was 2D all along
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.