Disrupting DeepFakes: Adversarial Attacks Against Conditional Image Translation Networks with...
Key Takeaways
The video discusses a research paper on disrupting DeepFakes using adversarial attacks against conditional image translation networks, with a focus on protecting images from being manipulated and used for nefarious purposes. The paper explores the use of adversarial attacks to prevent deepfakes and protect users' privacy.
Full Transcript
[Music] welcome to the 12 castes I'm your host Sam Cherrington hey what's up everyone before we move on to today's show I want to give you a heads up that we are back with another interactive podcast viewing party on Monday May 18th this time I'll be joined by Emily bender professor of linguistics at the University of Washington our recent interview explored the question of whether linguistics has been missing from NLP research we dig into questions like would we be making more progress on more solid foundations if more linguists were involved in modern NLP or is the progress we're making such as with deep learning models like transformers just fine we also explore issues like fairness bias and ethics and NLP and more Emily and I will be in the chat answering all of your questions about the interview will begin the viewing party at 3 o'clock Pacific on Monday you can head over to twill AI comm slash 376 viewing for more details or to add it to your calendar and now on to the show all right everyone I am here with Nathaniel Ruiz Nathaniel is a PhD student in image and video computing group at Boston University Nathaniel welcome to the twill a podcast thank you very much it's great to have a chance to chat with you I'm looking forward to digging into our topic which is some work you've recently done on disrupting deep fakes but before we dive into that you know tell us a little bit about your background and how you got started working in ml and AI yeah so the first kind of project that I did in AI was a computer vision project when I was doing an internship here at MIT and it was about basically detecting diseases in cassava plants and we were going to deploy the application in Uganda so that was kind of like my first introduction to deep neural networks and image processing type of stuff and I thought that was incredibly interesting just like the potential of these types of applications and this new technology right or this technology that had been advancing like very recently so I got really interested in it then I did my masters at Georgia Tech so that was right after that internship and then so at Georgia Tech I met a mentor and and my professor there it was my advisor for my Master's Jim ray and I joined this group and and did a lot of stuff so I got interested I guess and they do a lot of work on autism and behavioral imaging for autism trying to like diagnose or model behavior and attention in toddlers or kids so I thought that was was an example of a model that they'd built so we have we have several works on on so there were alright they were already doing several works on gaze estimation or attention estimation and when I joined that group I worked with Angie Chong one of my collaborators and she just graduated actually from that group and we did behavior modeling and and attention modeling and scene so now just more in general like if you're if you're looking at a person from a third person point of view like an image or a video of someone you can actually detect where they're attending in the scene and this work kind of generalizes and you can basically detect where the person is attending to in the scene and it could even be like if they turn their head this could pick up that type of attention towards the back of the room for example or if they're looking at the camera they're not looking at any object inside of the scene they're looking at something you know beyond the frame and it could also detect that type of attention so I got really basically interested in and faces mostly just in human beings and in faces in image and video so I think a lot of my work kind of like goes from that and then yeah that's how I got you know too recent kind of projects that I've been doing and how long have you been at B this is my second year so I thought a year and a half ago I started my PhD with my advisor Stan sclera what gachy's working on or looking at deep fakes so actually in the past year I was I was always very interested in deep fakes especially like there's a video where there's like defects of Obama using a lot of computer graphics right they use deep neural networks on computer graphics and this was like about like two or three years ago they're like some big advancements and you can see very realistic basically reanimations of Obama's face and that already you know got me very interested when I was at Georgia Tech but I think it didn't have like the technical expertise like really tackle it at that point and more recently I think the things that have been most impressive are the deep fake applications where you only grab using only one image of a person you can basically create more images or video of that person with different expressions and moving their head and that's been like really amazing I think there's a work by Samsung and they're all talking heads or something I don't actually remember the full title but it's just amazing how just with one image they can they can create these types of things so I had been working on generative models for faces recently and while I was working on that I had a conversation with Stan my adviser there's always a privacy issue right like when you're going to try to release a paper you have all these issues that whose faces can I actually use for this work and also kind of the reaction of the public and I think there's a lot of good that could come out of these applications but definitely a lot of bad that can come out of them right now the good part is you could have like actors and movies you could basically edit their their faces in real time and not ask them to shoot a scene again maybe if they like failed you know in their expression wasn't perfectly what you wanted at that point and there's a lot of of different you know cool applications that you can do with UI UX and and you know sending videos of yourself through through an iPhone or something but there's also really bad stuff that we've seen actually like the first thing that started happening is you know they've been using defects in pornography right just switching faces into printer graphic scenes and it's just you completely immoral and the potential for damage is so big so basically you know there's always that effect if you're publishing something on this topic that you could be helping people that want to do that you know so that whole thing was in my head all that time and during a conversation we're talking about the privacy issue so these networks are called image translation networks so this this work by Samsung is an image translation network that goes like from one image to you know a new image with a different expression imposed they also can fine-tune it with like several images but in general that's kind of the framework that a lot of these new works are are applying so star again also style again all of these organum ation also was it was a I think 2017 you see CV paper I think got guess the best paper and basically putting new expressions on a person's face so changing my expression from an image to be like smiling and you've seen like applications of this in apps like face at you know that's become very famous so this you know in a translation network is kind of simple is like a neural network that goes from an image to another image and you kind of specify what the output what you want it to be basically so and there's this all this other work on adversarial attacks right that everyone has been hearing because you know you don't want to have an adversarial attack is basically an imperceptible perturbation on an image that human being doesn't notice but that can completely full a neural network so you know this thing has been explored since 2013 for classifiers so if you had a neural network that tells you hey there's a pedestrian in the scene you know or not then you can fool this classifier so everyone is obviously freaked out about the possibility of this you know becoming a reality to attack you know no network in the wild with this type of thing so both of these like kind of fashionable ideas in my head I think you know it just popped out of nowhere like so maybe during that conversation maybe if we attack you know an image translation Network you'll be able to protect your images from from being converted into deep fakes the the premise of this work is you know it sounds like just like in the adversarial attacks you're injecting noise to an image our or you're injecting noise against an image and then disrupting the classifier here you're trying to inject noise on an image and disrupt the ability of some generative model to do whatever it's trying to do to manipulate that image is that the the general idea yeah exactly so in the classifier scenario you you have you know an image that goes into the class into the deep neural network and then you want a class that comes out of it so if it's a dog picture you want it to classify it as a dog right and an attack in that situation would be to make it classify it as you know a cat for example so a wrong class or you could be a targeted class like you wanted to actually always classify it as a cat you could do a targeted attack or an untargeted attack to like and drive it away from the class the dog class so it could be any other class like you know lizard the one that's closest so the closest boundary basically in this case it's some kind of like a more general it's a harder thing to quantify right if you have like an image translation network that goes from an image of a person you know my face you know like with a serious face and then someone wants me imagine just like basically this is one of the types of applications for this is imagine there's a picture of me in like a serious situation right and I'm like a political figure or something right and then someone grabs this image users guy animation which is you know it's working right now you could actually use this or start again or anything or cycle again and you and changes my expression into like a smiling expression right that's already directly an image to image deep fake that can have a lot of impact basically and the idea is to you know make this type of transformation impossible or basically the idea of our work is to make it either obvious or to completely disrupt the output such that it's too corrupted it's so easy to notice that it's been corrupted basically so the human observer can be like either doubt the source of the image or you know that that the image has been manipulated or it can you know or it's unusable basically it's like gibberish or black you know mmm that's basically the idea and so you make it sound so simple but I'm sure you know flipping through the paper there's a lot of work that went into this where you know what were the the challenging parts and and how did you take this from kind of idea to a working model yeah so I think actually the idea so what I loved about the idea is that it was so simple and it was so obviously useful that's what really got me excited at first right and it's actually you know the first like couple of weeks of implementing all this was actually not very hard because the the main idea of trying to destroy an output using an adversarial attack and an image translation Network it's actually a lot of these image translation networks are very susceptible to attack and some of them are a little bit more protected and maybe some of our future work is going to be on that type of thing like which architectures have more protection than others why are some difficult to attack and why are some easier to attack right but you know the paper so I think a lot of it went on you know a lot of the work on the paper went on showing that this is possible with a lot of different types of architectures showing a lot of very good examples that it's like a solid technique basically and you know there are some so basically this this paper is kind of like the first or one of the first steps into this kind of domain because in general so for this type of you know attack it's called a white box attack where you need to know all of the parameters of the neural network and you need to know the neural network that they're using right so that's a big you know kind of if in the real world this but definitely this could work at this moment you know because a lot of attacks or a lot of defects I'm sorry are very low effort so a lot of things happen where someone puts an architectural online on github right and then promotes that aren't read it for example and then a lot of people go and use this with this architecture with this pre-trained model and then you know create defects with this architecture right so that's kind of low effort that can already be preempted using this technology because you know that script kiddies I don't know if anyone uses that term anymore I think we should make a new one because what it's not that like you know with with hacking folks would just you know download some perl script or whatever and run it against some site to find you know vulnerabilities yeah exactly and you still had it's funny because you know I guess SQL injections were you know we're so easy to exploit in the early days but even until like you know like ten ten years ago or something like people were still finding SQL injection vulnerabilities and so script kiddies kind of like we're still able to like work in the real world so I think this kind of you know we should make a new term may be like DL kiddies or something right okay just be really first people trying to try to use like out-of-the-box kind of stuff on transfer learning kitties yeah very trained model kitties there's something in there somewhere but at the same time you know I always like I respect anyone that tries to use these things out of the box that's the first step right out of the box from you know wherever you can find put your hands on any of this technology and then start using and try to learn from it if it's not for doing something bad right if it's just to learn I encourage everyone right to just go on on github try a bunch of stuff and then see if they can modify it like that's the way forward right but yeah if you are doing deep fakes for an immoral purpose that's definitely not good yeah but this technology so just for this specific thing is already usable because we're able to you know find you're probably going to have the access to the to the weights and to the architecture but this is a very like constrained kind of attack in some sense the more advanced types of attacks are called blackbox attacks you could be like gray box where you know the architecture but you don't know the weights of the architecture or like different types there's different types of settings for that but the black box which is the most powerful is just you have a black box where you send an image and then you get an image back where you get you you're sent an image and you get like a class back the dog or something and then you're trying to kind of attack it without knowing almost anything about it I think that's really interesting and that's like where the promise lies in this because if someone can find very good black box attacks against a lot of these Mesonet methods then you'll definitely have something that that can work in the real world yeah yeah I mean you almost envision a scenario where you know a Facebook or Twitter Google like when you upload a photo it's applying this method to all of your photos so that they're not susceptible to you know being used for nefarious purposes 100% yeah yeah and that's like the first kind of application that I had in mind the first application that I had in mind was actually for celebrities where um you know their likenesses you know so you know it has actually has a big value right and a lot of people are targeting their pictures to try to modify them and that type of scenario where you can you know maybe you know they they can buy some type of service that protects their images and then yeah if you can generalize it then you can have any type of platform online that does this yeah and there's just so many interesting things right you could give permission to someone to use your picture and then to like modify your picture right and then there are some you know technologies that we've been thinking of in that direction as well lots of blockchain opportunities in there yeah I think a lot of people kind of jump to blockchain when they're thinking about protecting images of people or protecting media but that's one way this is another agenda bla and when I want to make a joke about overhype technologies yeah I mean we all fall into overhype sometimes um that's that's definitely true but I also think I don't know sometimes it brings attention that maybe will fade but it's still good that these kinds of domains are having a lot of attention because they have a lot of and the people that stick with it are the ones that are gonna make things happen and then the people that leave right okay well they left and if they they're not here to like make something happen then that's you know they're their issue basically so is the the noise that you're injecting is it parameterize with a single like a single epsilon value or their characteristics to the noise multiple you know characteristics that you're manipulating to make it work with a particular model yeah so the the main attacks that we propose so and the papers is not just attacking image translation systems for defects okay it's it has a lot of other stuff for example we have you know you have the image translation case but you also have the conditional case where I don't want to lose track of your question but I just want to say that we have basically several contributions then make it a little bit more than just oh this is you know a neat idea neat little idea right because I think the first kind of idea is is cool but also the all the contributions that we do make this like a kind of like bigger kind of type of work because the main idea of attacking these image translation systems it's actually not that complicated to adapt some of the techniques that we already had like F GSM fast grading sign method iterative F just and basically F GSM is just kind of taking a step in the direction of the of the gradient for for your image and then modifying your image so that you go away from the class that you want to classify this thing as that's for the classifier case right in our case you have the this loss which is you can have like your main metric is what happens if you translate the image without any attack you have kind of like a ground truth output right like this is what the picture is gonna look without any attack and then you have a translation of your image so this is the thing that we can modify because the translation of your image with an with an attack right that's the thing that we can modify you know you want the difference between this ground truth output and this attacked output to be as big as possible and we some kind of metric right and we use l2 and the formulation of our attacks but you could use you know a lot of different type of metrics and we use like an image image level metric which it goes like pixel pixel pixel to pixel differences and using l2 right and then you want to maximize this right you want your output the attacked output to be as different as possible as the ground truth output would have been so you can actually just do this it's just an optimization you know problem I guess one of the things that jumps to mind is as opposed to like in l2 distance maximizing the ability to fool some kind of discriminator network so we don't actually have to do that at all actually because so to train these these types of architectures yet you have a generator that does the image translation right and then you have a discriminator and this type of game between the discriminator that's creating the translation and the the generator sorry and the discriminator that's trying to detect whether it's a real or fake image is actually what makes the output so good and makes it you know approximate these distributions so well without it and without too much blurriness etc you know that's the power of Gans but we don't even need you know we kind of like throw away the discriminator in this process just use the generator and it just becomes like an optimization problem maybe the layer behind my question was is you know the your l2 distance is really a proxy for perceived difference from the actual face and I'm wondering like how good l2 is for you know really you know making the generated image far away from the face or you know perceived the level of perceived Distortion and so that's where I thought maybe like some kind of discriminator train discriminator thing could be better than l2 you but that's a really good question actually I think you know you could think of unlike an l2 distance you could you could think of you know the attack making just the image just a little bit brighter and then the l2 distance would go up right right but but so you'd have a higher l2 distance between these two but a human being would be like oh you know it's a little bit brighter but it's kind of still the same picture so yeah definitely it's not the perfect thing in the paper we explain why and on average you know it's it's a good metric to use and we show examples so we didn't really just go through the l1 l2 metric and be like yeah it's high so this it's working right we looked at a lot of qualitative examples but the second you know the second step that you can take after this is definitely and I you know encourage anyone that wants to try this out actually to try it out and because I'm trying other things so but if anyone wants to use like a perceptual metric so you know we have like vgg for example if you Gigi trained on faces is a pretty good kind of proxy or I mean it's kind of weird to say but it's kind of a proxy of perceptual of a perceptual metric so two faces that are similar in this like vgg sixteen feature space arm you know you can actually kind of cluster them better and in this in this type of sense instead of using l2 metrics so yeah having a higher distance with a vgg which is kind of like a discriminator in some sense it's a neural network right or you could do what you're saying is you could say is this image you know you could have like a discriminator I just had this idea right now actually you could have a discriminator that that tells you oh this image is more or less distorted right and you want you train your discriminator to detect distorted images and you train your generator to distort the images and then you could have like a game that in that way maybe with a second discriminator as well but definitely like that's that's one of the big questions of systematizing bise's it's easier to systematize with classifiers because you know when the class is wrong there's just a number right the class is four but we wanted five so it's wrong right in this case you you have something and that's the problem that I've been like bumping into all over this kind of area is um you're talking about human perception and trying to kind of like model a reaction of a human being right or or what the human being perceives in an image and you know much more complex for for generating faces and for disrupting defects right so I had started a a couple questions ago asking about like the how the noise is parameterised and and I think the question behind that question was you know is there you know some way to just crank the noise up as much as you can before the image starts looking distorted and use that as a way you know does that get you closer to a gray box or a black box type of scenario or do you really have to are there you know how nuanced is the does the noise have to be to defeat a particular system yeah that's actually a great question one thing that I really wanted to say that I didn't get a chance to say before we started it is um this is not just my work right like if this is work with really amazing collaborators that'd be you so a recent assist research assistant professor Sarah del barge all who helped me so much with this project and then my advisor Stan's Clara right and all these kind of ideas have been like discussed with them and you know we've all like put so much you know work into this right so okay go moving on from that basically yeah this is kind of like that questions really good because one of the things that we did was try it on so first of all just try to see how sensitive any of these architectures is to just random noise right like Gaussian noise or something and some of them are super sensitive if you I don't I don't really want to want to say which ones right because I don't want to just like single out any any and it's not their fault right but some some architectures if you inject just a little bit of random noise then you can have very big perturbations in the output image that was the first step and some of them are very resistant to it noise and then the this finding holds to the adversarial attack case so the an adversarial attack is just a sort of structured noise that is that is structured using you know basically you you use the gradient of of the the network to get the biggest type of disruption in the output possible right so that doing an adversarial attack of same magnitude would be way more effective than just random noise of that same magnitude but some architectures are just really sensitive to noise that's another lesson of this I think your initial response to that question was talking about the broader contributions to this paper beyond the kind of this simple deep fake disruption mechanism if that's a the right way to characterize it yeah that's walk us through the you know what you think are the the biggest contributions here this idea of attacking image translation systems is pretty natural but then there's some specific you know specificity of the fake kind of image translation networks and one of them is that you have you're always you almost always have a class or they're you know conditional image translation networks and your condition could be or your class could be for example in gonna mention you have the action units which are you know small movements of the face that could like correspond to like smiling or moving your lips upward etc right and then by combining them you create expressions so these these networks are conditional networks and you want to kind of attack them irrespective of the class so my attack doesn't have to if you know let's just take that you don't want it to only work on smiling faces or something exactly like yeah maybe this person is going to make everyone smile and pictures but you know you don't even know what the other person is going to do maybe close your eyes right so yeah for example if you target an attack towards and in some of these architectures you to attack towards one class then it doesn't transfer to other classes as well and in some of them it just an attack for one class just transfers completely to the others and I think actually these two kind of properties like the fragility to of Architecture to noise and this type of transfer are actually related that sounds kind of interesting and that is it kind of saying that the fragility isn't necessarily architectural trait but like more Pacific like a trait of the weights of an architecture yeah I think so I think the you know fragility of an architecture to attack is actually that's what I'm like kind of discovering now is tied not only to the type of architecture but to the weights and if you think about it the weights is just a function of the training data and the training kind of process right so the optimization process and the training data so these two things are pretty important I would say and it depends how important they are for each kind of architecture and it's still like this is you know complete yeah this is kind of like an intuition a little bit from what I've seen in my experiments but I think there's a lot of like super interesting work to be done here because I think adversarial attacks actually are very exciting to me and I've just gotten into them a little bit later but you know I've always like kind of wondered like how exactly do deep models work in some sense like why do they fail in certain cases and they don't fail in others you know this type of kind of explanatory process of of the failures of a network or how to make it better you know or you know intuitions and how to make it better so I think adversarial attacks are actually like a great window into into fragility of an explanation of these neural networks so that's one cool thing about this is by attacking image translation systems I can actually see in their output like when I attack them what they are doing a lot of them so for example you know this is a this is something good for a pretty specific I think but for star gann if you attack it then you have the whole image that changes all at once and you have other architectures such as the animation that are very targeted towards certain parts of the image that they're modifying so one architecture has learned how to kind of like change the whole frame at once and then what architecture has learned to do more like fine grained types of changes inside of an image and one is you know the animations more robust then star again so it's almost along the lines of work like lime and other things for your perturbing inputs or features and seeing how the network responds to the aim of understanding explained ability or producing an explanation you know this is your kind of almost at you know trying to explain or understand these networks through the disruptions that you're injecting yeah I think so I don't know I've actually this work you know I actually don't know about that work that that you that you just mentioned but you know going on from your explanation I don't know if that has been done maybe it's been done for like classifiers but I don't know if it's been done for image translation networks I think that's like a huge frontier that this kind of opens is to try to understand what's going on and then if you know so for example just you know example of the bat if you know that your your image translation network is changing the whole frame when you actually just need to change the hair color of the person then that you could think of this as a weakness right and then you could think of how do I change the architecture or the training procedure to correct this right and there are techniques to do it which are which are pretty cool I think so yeah it definitely is it's delving into this type of explain ability I guess that's also fashionable right now but I think it's a huge thing like my lab does a lot of of explain ability in deep networks ok ok so there's kind of broader understanding of these architectures is another contribution at the paper what else mmm yeah so yeah we were all that question kind of easy to get lost so that was that that was one of one of our contributions is conditional in the translation networks and and doing building attacks that generalize to all the different types of of classes so yeah it doesn't just work if someone's trying to put a smile on your face it also works when you're when someone's trying to close your eyes in an image or it doesn't just work if someone's trying to make you you know blonde or something it works also when someone tries to make your hair darker or something so that's that's one thing that the other thing is so kind of like okay now we have an attack typical in this kind of area is you have an attack what are the defense is right like what is someone that has like an actual like beneficial in a translation Network what can they do to defend against this type of attack because you could also think about the scenario where you know in this scenario you're trying to you know obstruct deep fake so you're trying to abstract something that is done without permission of the users and that can be malicious you can imagine a scenario where someone attacks let's say I don't know just off the top of my head like let's say you have like an an x-ray and and and you have like an image translation network that makes some zones more visible to a surgeon or whatever right like it's it's hard to come up with an example right now but going with that example you can imagine a malicious actor introducing one of our attacks or something like this to this x-ray to make the output not work right so what can a person do to defend against this and one of the defenses that holds up to all the scrutiny is adversarial training and I think it done by Madri at all and 2017 and that I think that's the paper so basically the idea is just it's very it's a it's a very simple very powerful idea you have PGD which is a very strong attack projected gradient descent and you just augment your data set with a lot of images that have been trained to have an attacked using PGD and then you train your neural network with those images and it gets it becomes a you know more robust to these types of adversarial attacks and this type of sense that I've been explaining and this also is so a lot of these defense mechanisms or you know defenses against adversarial techs are so hard to make because insecurity your defense has to be valid even when an attacker knows the defense you're going to use so a lot of Defense's fall apart and this in this scenario and this is one that that doesn't or hasn't at this point so one of the things is it's not foolproof we can still attack the network so we're able to do this adversarial training for ganz and we have like these formulations because you can you can you can train the generator with adversarial noise but you can also train the generator and the discriminator so you attack both the real image but you attack the real and the fake image so there's like different ways of doing it that the most powerful way of doing it is is doing the generator pose discriminator adversarial training and and it does defend against some certain types of attacks but so it makes it more robust but in the end if we have a very strong attack it's it's still pretty successful that's one thing that we learned and in the future more investigation this is kind of needed to see exactly you know how much robustness it does bring actually oh yeah and the last one I think all of these are pretty interesting and and you know I would like to work on all of them it's impossible right so that this one is I'm the last one is in in a student scenario where you can blur the and so my advisor just told me like oh okay you can attack these I'm just great but what happens in the real scenario if you're like a malicious actor you run into one of these images and you're like I suspect that this one's attacked right so I'll just blur it a little bit with you know a Gaussian blur or an average blur or something and then maybe since the attack is high frequency structure noise on top of the image then maybe this will destroy the attack and so that's one thing in this in our scenario it's it's different than the classifier scenario in our scenario we have to kind of also be careful this kind of like gray box it's an area where we don't we know maybe the architecture that they're using and the weights that they're using but we don't know what pre-processing they're using so there are some ideas in this domain like expectation over transformation where you just grab kind of like the expectation of all the losses through with all of the transformations that you think of and in that paper they did a cropping and rotating but they didn't do blurring so I think our papers one of the you know to the best of my knowledge is it's one that is one that addresses blurring and this type of scenario of transfer ability across blurring but also yeah because we noticed that blurring is actually really effective you blurt a naive attack just a little bit then you can definitely try and translate the image and there's almost no downside because the output image looks as good and we took when you say attack here are you speaking in the sense of kind of traditional adversarial attack or and or you know your work where you're trying to prevent manipulation which the manipulation is kind of an attack in this yeah the terminology is actually what we tried to do is is deep fake and deep faker right that's or manipulate you know and that's that's the the person who's trying to create the deep fake and then attacker an attack and disruption right is kind of the the person that's trying to yeah do an adversarial attack on the image to prevent the manipulation of it so in some sense the attackers defending against something done unto them in this scenario right but it's kind of hard to keep the terms yeah and then the funny thing is like defense is actually the deep faker that's trying to defend against you know the attacker right right all right yeah and in this case actually so in the pin the paper for the blurring thing we propose kind of like a different kind of iterative heuristic method which is faster than expectation over transformation but as effective for at least for our scenario and in that experiment that we did expectation over transformation is great work and all of these you know honestly all the works that I cite in that in in this paper are just are just really great and just like big steps and in this kind of field and I respect all those people like immensely so it's just hard to list all of the work that has kind of influenced what we do so the paper kind of explores these areas and what didn't we cover yet I mean I think I think we covered everything one of the things is that maybe neglected to say is that it's this is another really interesting kind of thing about the papers so if you have these blurring things so if you have different types of blur you can have like different magnitudes of the blur right and every time you're attacking a different kind of blur type you're attacking at a different type of kind of like scale if you think about it you're adding like higher and higher frequency noise and then you're adding lower and lower frequency noise so that's why we call so our attack is called spread spectrum attack and it kind of is inspired and spread spectrum and watermarking where you could put a watermark in a lot of different free in the frequency domain a lot of different kind of in the frequency band basically and not just not just in one but just in a spread you know spread spectrum manner this is kind of the idea of of that defense that we though we present in the paper yeah and just I don't know just for future work there's so much interesting stuff there are you continuing work on this or are you working on other projects now yeah definitely so I tried to like double my efforts in this because I feel like this is one of the projects that that has really given me you know a lot of ideas and different so many different directions so it's actually a little bit stressful because there's maybe a little a lot of ground to cover and if anyone is listening to this and wants to collaborate yeah just send me an email you can find it on the paper and then and we can set up a collaboration because I think you know there's at least like three to four directions that are very different but also super interesting well Nataniel thanks so much for taking the time to share a bit about what you're working on yeah thanks so much this is a great opportunity and very you know best of luck with all of your next shows and with all this craziness that's happening right now right yeah yeah yeah how are things for your staying staying inside staying safe all that yeah absolutely like everyone should stay inside as much as possible and just to go outside to shop or you know as much as you can right as much as like what allows again yeah but definitely here in Boston there's nothing going on everything's closed and bu has been closed you know I don't know maybe we'll be like this for forever on you know four months three months yeah who knows awesome well thanks so much and again take care all right how's it going all right everyone that's our show for today for more information on today's show visit when will a i.com slash shows as always thanks so much for listening and catch you next time [Music] you [Music]
Original Description
Today we’re joined by Nataniel Ruiz, a PhD Student in the Image & Video Computing group at Boston University.
We caught up with Nataniel to discuss his paper “Disrupting DeepFakes: Adversarial Attacks Against Conditional Image Translation Networks and Facial Manipulation Systems,” which will be presented at the upcoming CVPR conference. In our conversation, we discuss the concept of this work, which essentially injects noise into an image to disrupt a generative model’s ability to manipulate said image. We also explore some of the challenging parts of implementing this work, a few potential scenarios in which this could be deployed, and the broader contributions that went into this work.
The complete show notes for this episode can be found at twimlai.com/talk/375.
Subscribe:
Apple Podcasts:
https://tinyurl.com/twimlapplepodcast
Spotify:
https://tinyurl.com/twimlspotify
RSS:
https://twimlai.libsyn.com/rss
Full episodes playlist:
https://www.youtube.com/playlist?list=PLILZm3MRkvH83C46bZ4rPmB-jKWBltWkP
Subscribe to our Youtube Channel:
https://www.youtube.com/channel/UC7kjWIK1H8tfmFlzZO-wHMw?sub_confirmation=1
Podcast website:
https://twimlai.com
Sign up for our newsletter:
https://twimlai.com/newsletter
Check out our blog:
https://twimlai.com/blog
Follow us on Twitter:
https://twimlai.com/twimlai
Follow us on Facebook:
https://facebook.com/twimlai
Follow us on Instagram:
https://instagram.com/twimlai
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The TWIML AI Podcast with Sam Charrington · The TWIML AI Podcast with Sam Charrington · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Engineering Practical Machine Learning Systems with Xavier Amatriain - #3
The TWIML AI Podcast with Sam Charrington
How to Build Confidence as an ML Developer with Siraj Raval - #2
The TWIML AI Podcast with Sam Charrington
Open Source Data Science Masters, Hybrid AI, Algorithmic Ethics & More with Clare Corthell - #1
The TWIML AI Podcast with Sam Charrington
Interactive AI, Plus Improving ML Education with Charles Isbell - #4
The TWIML AI Podcast with Sam Charrington
Machine Learning for the Stars & Productizing AI with Joshua Bloom - #5
The TWIML AI Podcast with Sam Charrington
Generating Labeled Training Data for Your ML/AI Models with Angie Hugeback - #6
The TWIML AI Podcast with Sam Charrington
Explaining the Predictions of Machine Learning Models with Carlos Guestrin - #7
The TWIML AI Podcast with Sam Charrington
Deep Learning: Modular in Theory, Inflexible in Practice with Diogo Almeida - #8
The TWIML AI Podcast with Sam Charrington
Emotional AI: Teaching Computers Empathy with Pascale Fung - #9
The TWIML AI Podcast with Sam Charrington
Statistics vs Semantics for Natural Language Processing with Francisco Webber - #10
The TWIML AI Podcast with Sam Charrington
Building AI Products with Hilary Mason - #11
The TWIML AI Podcast with Sam Charrington
Reprogramming the Human Genome with AI, w/ Brendan Frey - #12
The TWIML AI Podcast with Sam Charrington
Understanding Deep Neural Networks with Dr. James McCaffery - #13
The TWIML AI Podcast with Sam Charrington
Scaling Deep Learning: Systems Challenges & More with Shubho Sengupta - #14
The TWIML AI Podcast with Sam Charrington
Domain Knowledge in Machine Learning Models for Sustainability with Stefano Ermon - #15
The TWIML AI Podcast with Sam Charrington
Machine Learning in Cybersecurity with Evan Wright - #16
The TWIML AI Podcast with Sam Charrington
Interactive Machine Learning Systems with Alekh Agarwal - #17
The TWIML AI Podcast with Sam Charrington
Location-Based Intelligence for Smarter Marketing with Klustera - #18
The TWIML AI Podcast with Sam Charrington
AI-Powered Customer Support with HelloVera - #18
The TWIML AI Podcast with Sam Charrington
Using AI to Simplify the Programming of Robots with Cambrian Intelligence - #18
The TWIML AI Podcast with Sam Charrington
Increasing Efficiency of Healthcare Insurance Billing with NLP, w/ Behold.ai - #18
The TWIML AI Podcast with Sam Charrington
Creating a Worldwide Financial Knowledge Graph with AlphaVertex - #18
The TWIML AI Podcast with Sam Charrington
From Particle Physics to Audio AI with Scott Stephenson - #19
The TWIML AI Podcast with Sam Charrington
Selling AI to the Enterprise with Kathryn Hume - #20
The TWIML AI Podcast with Sam Charrington
Engineering the Future of AI with Ruchir Puri - #21
The TWIML AI Podcast with Sam Charrington
Deep Neural Nets for Visual Recognition with Matt Zeiler - #22
The TWIML AI Podcast with Sam Charrington
Introducing Psycholinguistics into AI with Dominique Simmons- #23
The TWIML AI Podcast with Sam Charrington
Reinforcement Learning: The Next Frontier of Gaming with Danny Lange - #24
The TWIML AI Podcast with Sam Charrington
Offensive vs Defensive Data Science with Deep Varma - #25
The TWIML AI Podcast with Sam Charrington
Global AI Trends with Ben Lorica - #26
The TWIML AI Podcast with Sam Charrington
Intelligent Autonomous Robots with Ilia Baranov - #27
The TWIML AI Podcast with Sam Charrington
Reinforcement Learning Deep Dive with Pieter Abbeel - #28
The TWIML AI Podcast with Sam Charrington
Robotic Perception and Control with Chelsea Finn - #29
The TWIML AI Podcast with Sam Charrington
Natural Language Understanding for Amazon Alexa with Zornitsa Kozareva - #30
The TWIML AI Podcast with Sam Charrington
The Power of Probabilistic Programming with Ben Vigoda - #33
The TWIML AI Podcast with Sam Charrington
Intel Nervana Update + Productizing AI Research with Naveen Rao and Hanlin Tang - #31
The TWIML AI Podcast with Sam Charrington
Video Object Detection at Scale with Reza Zadeh - #34
The TWIML AI Podcast with Sam Charrington
Enhancing Customer Experiences with Emotional AI, w/ Rana el Kaliouby - #35
The TWIML AI Podcast with Sam Charrington
Expressive AI-Generated Music With Google's Performance RNN with Doug Eck - #32
The TWIML AI Podcast with Sam Charrington
Smart Buildings & IoT with Yodit Stanton - #36
The TWIML AI Podcast with Sam Charrington
Deep Robotic Learning with Sergey Levine - #37
The TWIML AI Podcast with Sam Charrington
Deep Learning for Warehouse Operations with Calvin Seward - #38
The TWIML AI Podcast with Sam Charrington
Cognitive Biases in Data Science with Drew Conway - #39
The TWIML AI Podcast with Sam Charrington
Data Pipelines at Zymergen with Airflow, w/ Erin Shellman - #41
The TWIML AI Podcast with Sam Charrington
Web Scale Engineering for Machine Learning with Sharath Rao - #40
The TWIML AI Podcast with Sam Charrington
Marrying Physics-Based and Data-Driven ML Models with Josh Bloom - #42
The TWIML AI Podcast with Sam Charrington
Machine Teaching for Better Machine Learning with Mark Hammond - #43
The TWIML AI Podcast with Sam Charrington
LSTMs, Plus a Deep Learning History Lesson with Jürgen Schmidhuber - #44
The TWIML AI Podcast with Sam Charrington
Learning From Simulated & Unsupervised Images through Adversarial Training - TWiML Online Meetup
The TWIML AI Podcast with Sam Charrington
Jennifer Prendki Interview - Agile Machine Learning - TWiML Talk #46
The TWIML AI Podcast with Sam Charrington
Evolutionary Algorithms in Machine Learning with Risto Miikkulainen - #47
The TWIML AI Podcast with Sam Charrington
Learning Long-Term Dependencies with Gradient Descent is Difficult - TWiML Online Meetup
The TWIML AI Podcast with Sam Charrington
Word2Vec & Friends with Bruno Gonçalves -#48
The TWIML AI Podcast with Sam Charrington
Symbolic and Subsymbolic Natural Language Processing with Jonathan Mugan - #49
The TWIML AI Podcast with Sam Charrington
Bayesian Optimization for Hyperparameter Tuning with Scott Clark - #50
The TWIML AI Podcast with Sam Charrington
Intel Nervana DevCloud with Naveen Rao & Scott Apeland - #51
The TWIML AI Podcast with Sam Charrington
AI-Powered Conversational Interfaces with Paul Tepper - #52
The TWIML AI Podcast with Sam Charrington
Topological Data Analysis with Gunnar Carlsson - #53
The TWIML AI Podcast with Sam Charrington
ML Use Cases at Think Big Analytics with Mo Patel & Laura Frølich - #54
The TWIML AI Podcast with Sam Charrington
Ray:A Distributed Computing Platform for Reinforcement Learning with Ion Stoica -#55
The TWIML AI Podcast with Sam Charrington
More on: Reading ML Papers
View skill →Related Reads
📰
📰
📰
📰
A lightweight workflow for keeping up with AI conference papers
Dev.to · Daniel
Why CitedEvidence Believes Great Researchers Read Less Than You Think
Medium · AI
How to Write a Literature Review That Actually Argues Something
Medium · Machine Learning
I Built a Personal Paper Engine to Stop Losing Research Papers
Dev.to · Ethan
🎓
Tutor Explanation
DeepCamp AI