breaking ais to make them better
Image recognition AIs are powerful but inflexible and cannot recognize images unless they are trained on specific data. In Raw Zero-Shot Learning, researchers give these image recognition AIs a variety of data and observe the patterns in their answers. The research team hopes that this methodology can help improve the robustness of future AI. Credit: Hiroko Uchida.

Today’s artificial intelligence systems used for image recognition are incredibly powerful with massive potential for commercial applications. Nonetheless, current artificial neural networks—the deep learning algorithms that power image recognition—suffer one massive shortcoming: they are easily broken by images that are even slightly modified.

This lack of “robustness” is a significant hurdle for researchers hoping to build better AIs. However, exactly why this phenomenon occurs, and the underlying mechanisms behind it, remain largely unknown.

Aiming to one day overcome these flaws, researchers at Kyushu University’s Faculty of Information Science and Electrical Engineering have published in PLOS ONE a method called “Raw Zero-Shot” that assesses how neural networks handle elements unknown to them. The results could help researchers identify common features that make AIs “non-robust” and develop methods to rectify their problems.

“There is a range of real-world applications for image recognition neural networks, including self-driving cars and diagnostic tools in healthcare,” explains Danilo Vasconcellos Vargas, who led the study. “However, no matter how well trained the AI, it can fail with even a slight change in an image.”

In practice, image recognition AIs are “trained” on many sample images before being asked to identify one. For example, if you want an AI to identify ducks, you would first train it on many pictures of ducks.

Nonetheless, even the best-trained AIs can be misled. In fact, researchers have found that an image can be manipulated such that—while it may appear unchanged to the human eye—an AI cannot accurately identify it. Even a single-pixel change in the image can cause confusion.

To better understand why this happens, the team began investigating different image recognition AIs with the hope of identifying patterns in how they behave when faced with samples that they had not been trained with, i.e., elements unknown to the AI.

“If you give an image to an AI, it will try to tell you what it is, no matter if that answer is correct or not. So, we took the twelve most common AIs today and applied a new method called ‘Raw Zero-Shot Learning,'” continues Vargas. “Basically, we gave the AIs a series of images with no hints or training. Our hypothesis was that there would be correlations in how they answered. They would be wrong, but wrong in the same way.”

What they found was just that. In all cases, the image recognition AI would produce an answer, and the answers—while wrong—would be consistent, that is to say they would cluster together. The density of each cluster would indicate how the AI processed the unknown images based on its foundational knowledge of different images.

“If we understand what the AI was doing and what it learned when processing unknown images, we can use that same understanding to analyze why AIs break when faced with images with single-pixel changes or slight modifications,” Vargas states. “Utilization of the knowledge we gained trying to solve one problem by applying it to a different but related problem is known as Transferability.”

The team observed that Capsule Networks, also known as CapsNet, produced the densest clusters, giving it the best transferability amongst neural networks. They believe it might be because of the dynamical nature of CapsNet.

“While today’s AIs are accurate, they lack the robustness for further utility. We need to understand what the problem is and why it’s happening. In this work, we showed a possible strategy to study these issues,” says Vargas.

“Instead of focusing solely on accuracy, we must investigate ways to improve robustness and flexibility. Then we may be able to develop a true artificial intelligence.” More information: Shashank Kotyan et al, Transferability of features for neural networks links to adversarial attacks and defences, PLOS ONE (2022). DOI: 10.1371/journal.pone.0266060 Journal information: PLoS ONE

Provided by Kyushu University Citation: Breaking AIs to make them better (2022, June 30) retrieved 30 June 2022 from This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no part may be reproduced without the written permission. The content is provided for information purposes only.


Podcast #690

First of all, if you’re here as a Josh Foodie Fan, turn back now. This week is very heavy on product reviews, though we do begin with our traditional Intel Arc news – and this time there’s a retail card available right here in the USA! As if this ...

View more: Podcast #690

Ultrathin dental camera inspired by insect-eye structure

A fully packaged ultrathin dental camera and multifunctional dental images. Credit: The Authors, doi 10.1117/1.JOM.2.3.031202. Conventional dental photography technology has had a limitation in using inconvenient tools such as mirrors and cheek retractors. Dentists require basic teeth images from various angles, such as right/left buccal and maxillary/mandibular occlusal, for ...

View more: Ultrathin dental camera inspired by insect-eye structure

Top 5 Smart Garage Door Openers

1. Chamberlain MyQ Smart Garage Door Opener 2. Garadget Smart Garage Door Controller 3. Nexx Smart WiFi Door Opener 4. GoControl Smart Garage Door Controller 5. Meross Smart Garage Door Opener Benefits Of A Smart Door Opener For The Garage Photo : Brandi Alexandra on Unsplash Few will deny ...

View more: Top 5 Smart Garage Door Openers

Scientists are discovering ways to eliminate PFAS, but this growing global health problem isn't going away soon

Credit: Pixabay/CC0 Public Domain PFAS chemicals seemed like a good idea at first. As Teflon, they made pots easier to clean starting in the 1940s. They made jackets waterproof and carpets stain-resistant. Food wrappers, firefighting foam, even makeup seemed better with perfluoroalkyl and polyfluoroalkyl substances. Then tests started detecting ...

View more: Scientists are discovering ways to eliminate PFAS, but this growing global health problem isn't going away soon

Forecasting the future to help protect monarch butterflies 

Credit: CC0 Public Domain The outlook for monarch butterflies isn’t great right now. In fact, the International Union for the Conservation of Nature, or IUCN, just added North America’s monarchs to its list of endangered species. With news like this, it can be easy to overlook the reasons to ...

View more: Forecasting the future to help protect monarch butterflies 

Grandoreiro banking malware targets manufacturers in Spain, Mexico

Starts with an email Grandoreiro features The notorious ‘Grandoreiro’ banking trojan was spotted in recent attacks targeting employees of a chemicals manufacturer in Spain and workers of automotive and machinery makers in Mexico. The malware has been active in the wild since at least 2017 and remains one of ...

View more: Grandoreiro banking malware targets manufacturers in Spain, Mexico

YouTube will watermark Shorts videos

The YouTube Shorts platform will begin adding watermarks to uploaded videos. Such a measure will help combat reposts of the same content on different sites. Following the explosion of TikTok, other internet companies have realized that short videos are extremely popular among the younger generation and have come up with ...

View more: YouTube will watermark Shorts videos

iQOO Neo 7 coming with Dimensity 9000+ and 120W charging

Vivo is preparing a bunch of new smartphones for the second half of 2022. Among them, the company has a new Vivo X Fold S that is likely to bring the Snapdragon 8+ Gen 1 SoC and the iQOO Neo 7. The latter will be the company’s next entry in ...

View more: iQOO Neo 7 coming with Dimensity 9000+ and 120W charging

The Company Bought 750 Acres In Costa Rica For $30 Million To Build A Sustainable Blockchain Project

Social network BeReal shares unfiltered and unedited moments from our lives—will it last?

New tool checks if in-app mobile browsers inject risky code on sites

Xiaomi’s revenue fell by 20% due to Chinese lockdowns

New Lindo Dual Camera Video Doorbell – end the porch piracy

Scientists take a deep dive into how sharks use the ocean

60 million years of climate change drove the evolution and diversity of reptiles

A third straight La Niña is likely—here's how you and your family can prepare

Stop dissing pessimism—it's part of being human

Built-in TikTok app browser caught adding tracking code to pages

Every She-Hulk episode will have a credits scene

Optimum Internet Review: Not the Best, Not the Worst Internet Service