Adversarial examples resulting from instability of current computer vision models are an extremely important topic due to their potential to compromise any application. In this paper we demonstrate that instability is inevitable due to a) symmetries (translational invariance) of the data, b) the categorical nature of the classification task, and c) the fundamental discrepancy of classifying images as objects themselves. The issue is further exacerbated by non-exhaustive labelling of the training data. Therefore we conclude that instability is a necessary result of how the problem of computer vision is currently formulated. While the problem cannot be eliminated, through the analysis of the causes, we have arrived at ways how it can be partially alleviated. These include i) increasing the resolution of images, ii) providing contextual information for the image, iii) exhaustive labelling of training data, and iv) preventing attackers from frequent access to the computer vision system.
翻译:对抗样本源于当前计算机视觉模型的不稳定性,因其可能危及任何应用而成为极其重要的课题。本文论证了不稳定性是不可避免的,原因包括:a) 数据的对称性(平移不变性);b) 分类任务的类别本质;c) 将图像本身视为物体进行分类的基础性矛盾。训练数据标注不完整进一步加剧了这一问题。因此我们得出结论:不稳定性是当前计算机视觉问题定义方式的必然结果。尽管该问题无法消除,但通过成因分析,我们找到了部分缓解途径,包括:i) 提高图像分辨率,ii) 为图像提供上下文信息,iii) 对训练数据进行穷举标注,iv) 阻止攻击者频繁访问计算机视觉系统。