Hacker News new | past | comments | ask | show | jobs | submit login

If the blob of knowledge consists of the weights of some neural network and if this blob is public... Then an attacker could easily perform imperceptible perturbation to the input in order to make the network believe that the yogurt is an Eiffel tower or vice versa. (Can't find the related publications right now but it appeared several times on hn before).

So if you don't want the system to be gameable, such public blobs of weights may need to be avoided.




Likely by that time we will have overcome this problem.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: