Skip to main content

That turtle is a gun! MIT scientists highlight major flaw in image recognition

Fooling Neural Networks in the Physical World
When is a rifle actually a 3D-printed turtle? When is an espresso actually a baseball? A fascinating, yet 
Recommended Videos
alarming new piece of research from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) shows that it’s possible to create objects that are able to trick Google image recognition algorithms into thinking they are looking at something else entirely.

In their paper, the team of MIT researchers describe an algorithm which changes the texture of an object just enough that it can fool image classification algorithms. The proof of what the team calls “adversarial examples” turns out to be baffling to image recognition systems, regardless of the angle the objects are viewed from — such as the 3D printed turtle which is consistently identified as a rifle. That’s bad news for security systems which use A.I. for spotting potential security threats.

“It’s actually not just that they’re avoiding correct categorization — they’re classified as a chosen adversarial class, so we could have turned them into anything else if we had wanted to,” researcher Anish Athalye told Digital Trends. “The rifle and espresso classes were chosen uniformly at random. The adversarial examples were produced using an algorithm called Expectation Over Transformation (EOT), which is presented in our research paper. The algorithm takes in any textured 3D model, such as a turtle, and finds a way to subtly change the texture such that it confuses a given neural network into thinking the turtle is any chosen target class.”

While it might be funny to have a 3D-printed turtle recognized as a rifle, however, the researchers point out that the implications are pretty darn terrifying. Imagine, for instance, a security system which uses AI to flag guns or bombs, but can be tricked into thinking that they are instead tomatoes, or cups of coffee, or even entirely invisible. It also underlines frailty in the kind of image recognition systems self-driving cars will rely on, at high speed, to discern the world around them.

“Our work demonstrates that adversarial examples are a bigger problem than many people previously thought, and it shows that adversarial examples for neural networks are a real concern in the physical world,” Athalye continued. “This problem is not just an intellectual curiosity: It is a problem that needs to be solved in order for practical systems that use deep learning to be safe from attack.”

Luke Dormehl
Former Digital Trends Contributor
I'm a UK-based tech writer covering Cool Tech at Digital Trends. I've also written for Fast Company, Wired, the Guardian…
How to buy Bitcoin
Faux bitcoin coin on a laptop.

Bitcoin is increasingly seen as a strong store of value, and a there are a range of different ways you can take advantage of its big swings in price to generate some profit for yourself, or create a digital nest egg for the future. But futures and ETFs aside, if you want to own your own Bitcoin, and follow the mantra of "Not your keys, not your coins," then you'll need to buy Bitcoin directly.

Fortunately, buying Bitcoin today is more straightforward than ever before, with a wide range of methods for doing so. Here's our favorite.

Read more
New report claims the PlayStation VR2 is in serious trouble
A side view of the PlayStation VR2, which sits on a wood table.

There have been a lot of signs that Sony hasn't been investing a lot of resources into VR, specifically its PlayStation VR2 headset, and according to a new report, the situation might be worse than previously believed.

In an Android Central article published Thursday, sources said that Sony was slashing budgets related to VR and that there would be "very few opportunities for VR game development" in the future. Another source mentioned that there were only two PSVR2 games in development at the company.

Read more
Wondershare Filmora: Understanding the Gen Z talent shaping influencer culture
Wondershare Filmora Gen Z in Action featured image

It is often said that younger generations can sometimes be hard to understand, in their approach to life and motivations. When it comes to modern influencer culture, content creation, and new, emerging technologies like AI, that indeed remains true. But thanks to a just-released documentary from Wondershare Filmora -- called Gen Z in Action -- we may have finally cracked the code. Okay, forgive my dry humor there. My generation is just as anomalous to older folks. The real focus here is Wondershare's documentary.

Filmed in Vancouver, British Columbia, it features in-depth reviews with over a dozen Gen Z content creators who have found success in their fields, including music, photography, and even cosplay. It delves into the lives of those creators, showcasing and honoring their dedication to their craft and personal innovations and exploring the unique challenges they face in today's hyper-digital landscape.

Read more