Brown’s adversarial patch paper came out in May [0] and was discussed a bit on HN [1].
But I’m wondering if anyone has used or seen reporting on use of these patches. They seem counterproductive digitally as, while difficult by algorithm, should be easy to flag for human review. So like wearing a sticker saying “I don’t want to be understood.”
But in real life seem useful for avoiding automatic detection as part of a crowd. I’m waiting to see these pop up like in events like the recent Paris tax riots.
[0] https://arxiv.org/pdf/1712.09665.pdf
https://arxiv.org/abs/1712.09665
[1] https://news.ycombinator.com/item?id=16704583