keyword
ImageNet models
ImageNet models are deep learning models, particularly convolutional neural networks and vision transformers, that have been trained on the ImageNet visual dataset to perform large-scale image classification and object recognition. These models learn rich visual representations from millions of labeled images spanning thousands of object categories, establishing them as standard benchmarks for evaluating computer vision architectures. In addition to direct image categorization, ImageNet models are extensively used as pretrained foundational architectures for transfer learning across specialized downstream visual tasks, as well as reference systems for studying visual generalization, model interpretability, and vulnerability to adversarial manipulation.
2 items

Adversarial Patch
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, Justin Gilmer
Why you should read this
Introduces printable, scene-agnostic adversarial patches capable of overriding deep learning image classifiers in the physical world to force the prediction of an arbitrary target class.
We present a method to create universal, robust, targeted adversarial image patches in the real world. The patches are universal because they can be used to attack any scene, robust because they work under a wide variety of transformations, and targeted because they can cause a classifier to output any target class. These adversarial patches can be printed, added to any scene, photographed, and presented to image classifiers; even when the patches are small, they cause the classifiers to ignore the other items in the scene and report a chosen target class. To reproduce the results from the paper, our code is available at this https URL
Added
2026-09-25

Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Anh Nguyen, Jason Yosinski, Jeff Clune
Why you should read this
Demonstrates that state-of-the-art deep neural networks can be easily fooled into classifying human-unrecognizable images as familiar objects with near 100% confidence, exposing fundamental differences between machine and biological vision.
Deep neural networks (DNNs) have recently been achieving state-of-the-art performance on a variety of pattern-recognition tasks, most notably visual classification problems. Given that DNNs are now able to classify objects in images with near-human-level performance, questions naturally arise as to what differences remain between computer and human vision. A recent study revealed that changing an image (e.g. of a lion) in a way imperceptible to humans can cause a DNN to label the image as something else entirely (e.g. mislabeling a lion a library). Here we show a related result: it is easy to produce images that are completely unrecognizable to humans, but that state-of-the-art DNNs believe to be recognizable objects with 99.99% confidence (e.g. labeling with certainty that white noise static is a lion). Specifically, we take convolutional neural networks trained to perform well on either the ImageNet or MNIST datasets and then find images with evolutionary algorithms or gradient ascent that DNNs label with high confidence as belonging to each dataset class. It is possible to produce images totally unrecognizable to human eyes that DNNs believe with near certainty are familiar objects, which we call "fooling images" (more generally, fooling examples). Our results shed light on interesting differences between human vision and current DNNs, and raise questions about the generality of DNN computer vision.
Source
http://yosinski.com/media/papers/Nguyen__2014__arXiv__Deep_Neural_Networks_are_Easily_Fooled.pdfAdded
2026-09-11
