I just checked out the supp figs. Maybe I’m reading it wrong, but it looks like the images were corrupted without reference to the model, right? As opposed to doing gradient descent in pixel space to find the minimal corruption to fool the model which is what I believe Patrick did to his chihuahua.
Yeah exactly! In this paper just a test of robustness, but in unpublished we did style transfer stuff, but can’t defend it that much :)) just causal convo here
Comments