Adversarial examples for the OpenAI CLIP in its zero-shot classification regime and their semantic generalization | Stanislav Fort
It turns out that adversarial examples are very easy to find (<100 gradient steps typically) for the OpenAI CLIP model in the zero-shot classification regime. Those adversarial examples generalize to semantically related text descriptions of the adversarial class.
It turns out that adversarial examples are very easy to find (<100 gradient steps typically) for the OpenAI CLIP model in the zero-shot classification regime. Those adversarial examples generalize to semantically related text descriptions of the adversarial class. Stanislav Fort ( Twitter and GitHub ) TL;DR: Adversarial examples are very easy to find for the OpenAI CLIP model in its zero-shot classification regime. Those adversarial examples generalize surprisingly well to semantically-related descriptions of the adversarial class. I wrote a Google Colab where you can try it for yourself. 1. I
related reading
- CLIP · Hugging Facehuggingface.co
- Replicate - Run AI with an APIreplicate.com
- openaccess.thecvf.com/content/ICCV2023/papers/Li_Your_Diffusion_Model_is_Secretly_a_Zero-Shot_Classifier_ICCV_2023_paper.pdfopenaccess.thecvf.com
- Some Lessons from Adversarial Machine Learning | FAR.AIfar.ai
- [2005.14165] Language Models are Few-Shot Learnersarxiv.org
- Nicholas Carlininicholas.carlini.com
- [1610.00768] Technical Report on the CleverHans v2.1.0 Adversarial Examples Libraryarxiv.org
- Adversarial Examples Are Not Bugs, They Are Features – gradient sciencegradientscience.org
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailmentarxiv.org
- Hugging Face – The AI community building the future.huggingface.co
- An Image is Worth One Word: Personalizing Text-to-Image Generation using Textual Inversiontextual-inversion.github.io
- 2306.15447.pdfarxiv.org