Skip to main content

AI image recognition fooled by single pixel change

3D printed turtleImage copyrightANISH ATHALYE
Image captionThis turtle can sometimes look like a rifle to some image recognition systems
Computers can be fooled into thinking a picture of a taxi is a dog just by changing one pixel, suggests research.
The limitations emerged from Japanese work on ways to fool widely used AI-based image recognition systems.
Many other scientists are now creating "adversarial" example images to expose the fragility of certain types of recognition software.
There is no quick and easy way to fix image recognition systems to stop them being fooled in this way, warn experts.

Bomber or bulldog?

In their research, Su Jiawei and colleagues at Kyushu University made tiny changes to lots of pictures that were then analysed by widely used AI-based image recognition systems.
All the systems they tested were based around a type of AI known as deep neural networks. Typically these systems learn by being trained with lots of different examples to give them a sense of how objects, like dogs and taxis, differ.
The researchers found that changing one pixel in about 74% of the test images made the neural nets wrongly label what they saw. Some errors were near misses, such as a cat being mistaken for a dog, but others, including labelling a stealth bomber a dog, were far wider of the mark.
The Japanese researchers developed a variety of pixel-based attacks that caught out all the state-of-the-art image recognition systems they tested.
"As far as we know, there is no data-set or network that is much more robust than others," said Mr Jiawei, from Kyushu, who led the research.
Nerve cellsImage copyrightSCIENCE PHOTO LIBRARY
Image captionNeural networks work by making links between massive numbers of nodes

Deep issues

Many other research groups around the world were now developing "adversarial examples" that expose the weaknesses of these systems, said Anish Athalye from the Massachusetts Institute of Technology (MIT) who is also looking into the problem.
One example made by Mr Athalye and his colleagues is a 3D printed turtle that one image classification system insists on labelling a rifle.
"More and more real-world systems are starting to incorporate neural networks, and it's a big concern that these systems may be possible to subvert or attack using adversarial examples," he told the BBC.
While there had been no examples of malicious attacks in real life, he said, the fact that these supposedly smart systems can be fooled so easily was worrying. Web giants including Facebook, Amazon and Google are all known to be investigating ways to resist adversarial exploitation.
"It's not some weird 'corner case' either," he said. "We've shown in our work that you can have a single object that consistently fools a network over viewpoints, even in the physical world.
A countryside scene
Image captionImage recognition systems have been used to classify scenes of natural beauty
"The machine learning community doesn't fully understand what's going on with adversarial examples or why they exist," he added.
Mr Jiawei speculated that adversarial examples exploit a problem with the way neural networks form as they learn.
A learning system based on a neural network typically involves making connections between huge numbers of nodes - like nerve cells in a brain. Analysis involves the network making lots of decisions about what it sees. Each decision should lead the network closer to the right answer.
However, he said, adversarial images sat on "boundaries" between these decisions which meant it did not take much to force the network to make the wrong choice.
"Adversaries can make them go to the other side of a boundary by adding small perturbation and eventually be misclassified," he said.
Fixing deep neural networks so they were no longer vulnerable to these issues could be tricky, said Mr Athalye.
"This is an open problem," he said. "There have been many proposed techniques, and almost all of them are broken."
One promising approach was to use the adversarial examples during training, said Mr Athalye, so the networks are taught to recognise them. But, he said, even this does not solve all the issues exposed by this research.
"There is certainly something strange and interesting going on here, we just don't know exactly what it is yet," he said.

Comments

Popular posts from this blog

Why Do We Always Screw Up When Someone’s Watching?

Source: OMGfacts Julian Larach Follow Writer @Dose and @OMGFacts. Here to help you procrastinate. Instagram: Julian_Larach Aug 11 Raise your hand if you’ve totally forgotten how to type when your boss is watching. Some nights I have trouble falling asleep because of the embarrassment I still feel after a horrific incident that landed me a shameful black eye. I attended a junior Olympic diving competition in Montréal as a teenager. It wasn’t until I got up on the platform that I began to panic. Everyone was watching me. The onlookers were divers from around the world who were destined to be olympians, world champs, or, I don’t know, future Instagram celebs. As many times as I had drilled the hell out of this dive during practice, somehow, I managed to drop the ball in front of the wrong crowd. Let’s just say that “belly-flop” is a sugar coated version of what happened. But basically, my muscle memory vanished. I landed flat on my stomach and was gifted with a mortifying...

Most Dangerous Jobs In The World

If you are looking for a more adventurous job and you are considering one from the list below, you should think twice. They might sound romantic, exciting, and well paid, but "dangerous" describes them best. We made a list of the most dangerous jobs in the world. Which one do you think sounds the most frightening? 10. Snake Milker flickr.com Source:  Snake milkers spend their days pushing snakes (certain types only) into a plastic container to extract or milk the snake. Snake venom (poison) can be used for many things, but the most important is its use in medical research or to produce "antivenom." Even though safety measures are applied, each milking process is highly dangerous. The rate of milkers who haven’t been bitten on the job is surprisingly low. Average annual salary:  $30,000 9. Courier flickr.com Source:  Surprisingly, being a...

The 10 Most Dangerous Waters in the World

Most people can’t imagine their vacation without some body of water nearby, be it a lake or an ocean. But there are waters on our planet that can be deadly for revelers. Bright Side  would like to tell you about several places on Earth whose beauty is only for watching from a safe distance. And for those who aren’t satisfied with these, scroll to the end of the article for a savory bonus. 10. Great Blue Hole, Belize © Seann McAuliffe/flickr    Tides turn the  Great Blue Hole  into a huge vortex that draws in everything on the surface, while ebbs make it spout huge columns of water. Despite all this, though, there still are many who want to see this hole because Jacques Cousteau himself called it one of the best places for diving on Earth. 9. Jacob’s Well, Texas, USA © imgur     © wikipedia   ...