"Adversarial perturbations" reliably trick AIs about what kind of road-sign they're seeing

If you are worried about people vandalising road signs you can vandalise them to fool humans too. At least the AI classifier successfully flags up that the sign has been tampered with with the reduced confidence value.

Anyway, TASbot plays Brain Age was a pretty good segment on adversarial inputs to simple classifiers.

To be honest, I don’t really see what the point of this study is. If you are allowing people to physically deface signs, then the easy thing to do for a vandal is to just cover the sign with a different sign. That fools everyone, AI or human, and will be difficult for any investigator to notice and deal with without knowing what the sign was originally supposed to be.