Comment by kaba0
4 years ago
Why do you think that? There are plenty of whitepapers on fooling NNs by changing random pixels by a bit, so that the picture is not meaningfully changed for a person, but the computer will label it very differently. Do note that these are not cryptographic hashes because they have to recognize the picture even when compressed differently, cropped a bit, etc.
Ok, but that’s not the result of a random collision. Those are all carefully engineered.
What is the actual attack you are imagining?