Why aren’t adverserial inputs used more widely for captchas?
Different models have different adverserial examples?
There are only a known adverserial examples for a given model (discovering them takes time), and can easily just be manually enumerated?
Why aren’t adverserial inputs used more widely for captchas?
Different models have different adverserial examples?
There are only a known adverserial examples for a given model (discovering them takes time), and can easily just be manually enumerated?