Our very own attempts to deceive Tinder might possibly be considered a black colored field assault, because the as we can upload one picture, Tinder does not provide us with any information on how they tag the newest photo, or if perhaps they usually have linked our very own account regarding record
The fresh new math below the pixels basically claims we wish to maximize ‘loss’ (how lousy brand new prediction are) according to research by the enter in study.
Within this example, the fresh new Tensorflow records mentions that this is actually a beneficial ?white container assault. Thus you’d complete usage of understand the input and you will output of your own ML design, in order to figure out which pixel change for the new photo feel the greatest change to how design classifies the latest visualize. The container are “ white” since it is clear just what efficiency try.
That being said, certain approaches to black colored box deceit basically advise that whenever lacking information regarding the real design, you should try to work on replacement designs you have greater access to to help you “ practice” picking out smart type in. With this in mind, it could be that static created by Tensorflow to help you fool the individual classifier may also deceive Tinder’s design. Continue reading