Pith. sign in

REVIEW 3 cited by

Going Grayscale: The Road to Understanding and Improving Unlearnable Examples

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2111.13244 v1 pith:US5S7BIA submitted 2021-11-25 cs.CV cs.CR

classification cs.CVcs.CR
keywords uleosulesadversarialexamplesgrayscaleimagestrainingunlearnable
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent work has shown that imperceptible perturbations can be applied to craft unlearnable examples (ULEs), i.e. images whose content cannot be used to improve a classifier during training. In this paper, we reveal the road that researchers should follow for understanding ULEs and improving ULEs as they were originally formulated (ULEOs). The paper makes four contributions. First, we show that ULEOs exploit color and, consequently, their effects can be mitigated by simple grayscale pre-filtering, without resorting to adversarial training. Second, we propose an extension to ULEOs, which is called ULEO-GrayAugs, that forces the generated ULEs away from channel-wise color perturbations by making use of grayscale knowledge and data augmentations during optimization. Third, we show that ULEOs generated using Multi-Layer Perceptrons (MLPs) are effective in the case of complex Convolutional Neural Network (CNN) classifiers, suggesting that CNNs suffer specific vulnerability to ULEs. Fourth, we demonstrate that when a classifier is trained on ULEOs, adversarial training will prevent a drop in accuracy measured both on clean images and on adversarial images. Taken together, our contributions represent a substantial advance in the state of art of unlearnable examples, but also reveal important characteristics of their behavior that must be better understood in order to achieve further improvements.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DiffUE: Enhancing Utility-Unlearnability Trade-off of Unlearnable Examples via Diffusion Autoencoders

    cs.CV 2026-07 conditional novelty 6.5 of 10

    Injecting defensive noise into the semantic latent of a diffusion autoencoder produces unlearnable images with superior quality-unlearnability trade-off and robustness to relearning attacks versus pixel-space baselines.

  2. Adversarial Attacks for Good: A Survey of Proactive Protection across the Visual Content Lifecycle

    cs.CR 2026-08 accept novelty 5.0 of 10

    The paper unifies privacy filters, unlearnable examples, generative safeguards, adversarial CAPTCHAs, and provenance marks into a single 'adversarial attacks for good' lifecycle and evaluates them along three common axes.

  3. Securing Traffic Sign Recognition Systems in Autonomous Vehicles

    cs.CV 2025-06 conditional novelty 4.0 of 10

    Error-minimizing poisoning can crash traffic sign classifiers from 99.9% to 10.6% accuracy, and a nonlinear-transform augmentation defense restores it to ~96% while beating adversarial training.

Pith tools