Path: csiph.com!eternal-september.org!feeder.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail From: rami18 Newsgroups: comp.programming.threads Subject: Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks Date: Wed, 26 Jul 2017 14:39:58 -0400 Organization: A noiseless patient Spider Lines: 24 Message-ID: Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Injection-Date: Wed, 26 Jul 2017 18:35:56 -0000 (UTC) Injection-Info: mx02.eternal-september.org; posting-host="67c57891d4bfc27855b262f2c6659403"; logging-data="26792"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+AfAhFhCifWW3f8l5uc+Jl" User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1 Content-Language: en-US X-Mozilla-News-Host: news://news.eternal-september.org:119 Cancel-Lock: sha1:CHEyaFYGbjmVvK4ie2cH+hQH3gQ= Xref: csiph.com comp.programming.threads:3853 Hello... Read this: Adversarial perturbations are not "natural" images. They are regular and just don't occur in nature. This is possibly the most important unexplained aspect of neural networks and machine learning and it is being studied as a security or safety problem. What is some evil person misleads a machine intelligence? What if a self driving car is made to crash because an adversarial signal is injected into the video feed? Here is an interesting paper about it: Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks https://arxiv.org/pdf/1511.04508.pdf Thank you, Amine Moulay Ramdane,