Skip to content

Comment on Adversarial Reprogramming of Neural Networksparent

Comments

I appreciate that your comment was tongue-in-cheek, but note that what you propose is actually a case of a standard targeted adversarial attack (changing a label prediction from "ped x-ing" to "stop"). This is fundamentally different from what's being proposed in the paper, which is to repurpose an existing NN (and its output labels) to perform another task altogether.

I'm still trying to figure how it could possibly be useful... the authors suggest it could be used to "steal resources", but it seems a bit contrived.

Well, if you could transform your problem into the "stop" vs. "ped x-ing" problem, you could let the future smart self-driving cars solve it for you. Maybe they have more computational resources than you can muster (but that sounds very contrived, even if you could somehow harness the computational power of a freeway full of future cars). Or you could imagine another very contrived case where some self-driving car company controls some important algorithm you need to solve your problem via a patent and it would be illegal to solve your problem otherwise (also very contrived...).

how it could possibly be useful

1 create a GPU friendly cryptocurrency where the payload includes a two dimensional data set (or image) that is processed with a standardized neural network model

2 let programmers pay a mining fee to expedite execution

3 instead of GPUs doing nothing but redundant calculations and getting replaced by ASICs, mining GPUs can dual purpose mine and execute arbitrary code

Will it be efficient, probably not. It does kill two birds with one stone

It would be useful to anyone looking to cause havoc, terror, and/or harm.

It could be the beachhead of a larger attack. You could use the model's authority to steal its data or gain access to other resources.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.