Jul 2026
A New Kind of Adversarial Example: Measuring the Human-Model Gap, and Its Relationship to OOD Detection
This work studies the opposite of an imperceptible perturbation to fool a model: a large, clearly visible perturbation that causes the model to keep its original, correct prediction, even though a human would no longer recognize the image.
A. Borji
· arXiv.org · 0 citations