Legacy
The latest and greatest in Adversarial Examples
-03-05
Note: this is an archived blog post from 2021-03-05, kept here for completeness. It may be outdated and does not necessarily reflect my current views.
Too funny not to share, the latest and greatest adversarial examples to fool OpenAI CLIP look like … this:

CLIP is fooled by an adversarial patch, i.e. putting text in the images. Or as someone on twitter put it: better wear your „I am not robbing this bank“ t-shirt the next time you attempt to rob a bank.
More in the OpenAI blog: https://openai.com/blog/multimodal-neurons/