I don’t have much to say here, especially since I don’t want to rehash the old arguments about the usefulness of prosaic adversarial ML research. (I think it’s worth working on but the direct impacts of the work are unclear). I do think that most people in AIS agree that image advexes are challenging and generally unsolved, but the people who disagree on the relevance of this line of research tend to question the implied threat model.
Glad to see that this work is out!
I don’t have much to say here, especially since I don’t want to rehash the old arguments about the usefulness of prosaic adversarial ML research. (I think it’s worth working on but the direct impacts of the work are unclear). I do think that most people in AIS agree that image advexes are challenging and generally unsolved, but the people who disagree on the relevance of this line of research tend to question the implied threat model.