> If brain activations are insensitive to subtle adversarial attacks, we would expect people to choose each picture 50% of the time on average. However, we found that the choice rate—which we refer to as the perceptual bias—was reliably above chance for a wide variety of perturbed picture pairsOk, but the article doesn’t say what was the actual rate?
jaschasd|2 years ago
The effect strength on humans ranges from a few percent deviation of human judgements from chance for subtle adversarial perturbations (epsilon=2), to ~15% deviations of human judgement from chance for large magnitude perturbations in the largest magnitude experimental condition.