Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Without knowing much about ML, it seems that using two (or more) very different methods could be a reasonable defense; if the methods are sufficiently different then it will get exponentially harder to find a gradient that fools all the methods; what to do when the outputs strongly disagree is a good question, but switching to a failsafe mode seems better than what we have now.


These adversarial inputs have been shown to generalize to separately trained models.


I was thinking use the same training set but different ML techniques; It's been almost 20 years since I took an AI class, but RNNs weren't the only thing in there...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: