• Zaktor@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    Blur+Sharpen isn’t what Nightshade is doing, it’s an example of a passive defense technique that may mess up fine-tuned “invisible” attacks because they rely on making minimal changes to jump category, and that can often come in the form of pretty precise pixel changes. You may have seen past papers about making pandas classify as gibbons. They rely on introducing a noise mask that just makes the image look a little worse quality, but in total is enough to flip the category. They don’t really define their perturbation method in this paper, but there’s some tension between being “invisible” and being resilient to “invisible” corrections like suggested above.

    • Kogasa
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Oh, blur+sharpen to mitigate Nightshade makes sense, yeah.