skip to content

Through the Lens

A perturbation that works on a tensor is usually destroyed by a lens and a codec. Interviewers ask because simulation numbers get quoted as if the capture pipeline were not part of the model.

on this pageshow

explore

questions

4

Why does a perturbation that flips an image classifier on a file usually fail once printed and photographed?

level: juniorimportance: must knowfreq 60%

answer

  1. the model never sees your file
  2. print, lens, light, resize, re-encode
  3. a fragile direction, not a robust shape
  4. every stage runs before inference
  5. amplitude cannot restore lost detail

basics

~20 s

A digital perturbation is a precise pattern of tiny per-pixel changes. Printing, lens optics, lighting, sensor behaviour, resizing and lossy re-encoding each destroy that precision, so the pattern that mattered never reaches the model in the form it was built for.

solid answer

~50 s

The attacker's perturbation is not noise; it is a specific low-amplitude direction read off the loss with respect to the input, and its effect depends on the exact pixel values arriving at the model. When the artefact is printed and read by a camera, a whole chain runs before inference: halftoning and gamut clipping at the printer, geometry and focus at the lens, illumination and shadow, sensor noise and auto-exposure, then a resize to the model's input size and usually a lossy re-encode. Each of those is a transformation the perturbation was never optimised to survive, and the resize plus re-encode alone low-pass away most fine structure. So a success rate measured on the file is not a prediction about the gate. A physical attack has to be built against those transformations from the start, and what survives is far weaker at the same nominal budget.

go deeper

for a junior

Be ready to say what actually sits between a printed surface and the model: printing, lens and angle, lighting, sensor, a resize and a lossy re-encode. Naming that chain is most of the answer at this level.

for a middle

Explain why the loss is spatial rather than amplitude-based, and why a perturbation is a specific direction while random noise of the same size does nothing. Interviewers expect you to reject the bigger-perturbation fix and say what replaces it.

for a senior

Demonstrate that you never read a digital success rate as a field estimate. Say what experiment you would insist on instead, and which stage of a specific deployed capture chain you would ablate first.

for a principal

Own the framing that a lab number and a field number describe different input distributions, and that your organisation should not accept the first as evidence about the second in a risk decision or a vendor claim.

## The thing the attacker actually built An adversarial perturbation is a **direction**, not noise. It is computed from the gradient of a loss with respect to the *input* (not the weights), and it works because a trained classifier's decision surface is extremely sensitive along a few particular directions and almost insensitive along most others. That is why a structured change far too small to see can flip a confident prediction while **random** noise of the same magnitude essentially never does. The whole effect lives in the precision: which pixels moved, by how much, in which direction, relative to each other. That precision is exactly what a camera does not preserve. ## What sits between the attacker's artefact and the model When the sensor is the only way in — a printed marking presented to a gate reader, a sticker in a scene, a sheet held up to a kiosk — the model never sees the attacker's file. It sees the output of a chain, and every stage is a transformation applied *before* inference: - **Reproduction.** A printer has a limited gamut and prints with halftone dots on a substrate with its own texture and gloss. Values outside the gamut are clipped; sub-dot detail does not exist at all. - **Geometry.** Angle, distance and lens focus rescale, skew and blur the surface. A pattern designed at one pixel scale arrives at another, resampled. - **Illumination.** Colour temperature, shadow, specular highlight and glare shift and locally destroy contrast, differently at each hour of the day. - **Sensor and exposure.** Photon and read noise, auto-exposure, auto white balance and sharpening all alter values before anything is stored. - **Pipeline.** The frame is resized to the model's input resolution and, in most deployed chains, passes through at least one lossy encode/decode step. A resize and a lossy re-encode by themselves act as a low-pass filter with quantisation. A perturbation whose effect is carried by high-frequency, sub-pixel-scale structure is largely gone by the time the tensor exists. ## Why turning the amplitude up is not the answer The intuitive fix — make the perturbation bigger — helps a little and fails for two reasons. First, amplitude does not buy you back structure: blur and resampling remove *spatial detail* regardless of how strong it was, and printing cannot reproduce values it cannot mix. Second, magnitude is bounded by the attack being usable at all — a marking that has been visibly destroyed gets rejected by a human, and on a physical artefact the real constraint was never a small distance budget anyway; it is how much area and viewpoint the attacker controls, and what a person looking at it will accept. The workable approach is different in kind: optimise the artefact so that it works **in expectation over the transformations a real capture applies**, sampling angle, lighting, print reproduction, resize and re-encode during the search rather than solving for one clean tensor. That changes what the artefact looks like — larger, lower-frequency, higher-contrast, spatially redundant — and it changes what you can achieve, because you are now asking one artefact to satisfy many conditions at once. ## The number that matters, and the one that does not This is why "99% success" from a digital evaluation is not evidence about a camera. Those are two different experiments over two different input distributions. Physical results are reported as a **rate over presentations under a named set of conditions** — angles, distances, illumination, camera, capture settings — and they are routinely far below the digital figure for the same attack idea. Each additional condition the artefact must survive costs some of that rate. For a candidate, the takeaway is a habit rather than a fact: when someone shows you a physical evasion result, ask what the model actually received. If the answer is "the perturbed file", the capture chain was never in the experiment, and the claim is about a file, not about a gate.

  • Why doesn't simply increasing the perturbation magnitude fix this?
    Because the loss is mostly spatial, not amplitude-related. Blur, resampling to the model's input size and lossy re-encoding remove fine structure however strong it was, and a printer cannot reproduce values outside its gamut. A larger change also becomes visible, and a physical artefact is bounded by area, viewpoint and what a person will accept rather than by a small distance budget. The fix is to optimise against the transformations themselves.
  • Which stage of the chain usually costs the most success rate?
    It depends on the chain, which is why you measure rather than assume. In practice geometry and illumination dominate for a surface read at varying angles outdoors, while the resize to the model's input resolution plus a lossy encode dominate when the presentation is head-on and well lit. The honest answer in an interview is that you ablate the chain stage by stage and report which one the rate collapses at.
  • Does this mean physical evasion is not a real risk?
    No. It means the digital number is not the risk estimate. Artefacts built against the capture distribution from the start do work at meaningful rates, and where an attacker can present repeatedly at low cost, even a modest per-presentation rate is a practical attack. The correction is to the measurement, not to the threat.

It is like a signature forged at the level of individual ink fibres: perfect on the original sheet, meaningless once the page has been printed, photographed under a desk lamp and shrunk to a thumbnail.

saying these in an interview costs you the question

  • Assumes a simulated success rate transfers to a real camera
  • Calls an adversarial perturbation random noise
  • Thinks a larger perturbation radius alone survives capture
  • Believes the model sees the attacker's file
  • Treats printing as just one more small distortion

context

open as a page

Why does an attacker printing a marking for a gate camera optimise over many capture conditions at once?

level: middleimportance: should knowfreq 48%

basics

~20 s

Because the artefact has to work after the capture chain, not before it. Optimising for expected success across sampled angles, distances, lighting, print reproduction, resize and re-encode buys durability, and each condition added to that set costs achievable success rate.

open as a page

A printed marking opens a camera-controlled gate once in five presentations — how do you report that finding?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Report a rate over presentations together with the conditions it was measured under: angle and distance range, lighting, camera and capture settings, and how many trials. Intermittence is the expected shape of a physical attack, not evidence that it does not work.

open as a page

A camera firmware change cut a physical evasion finding's success rate to near zero — do you close it?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

No. A capture-setting change moved the transformation distribution the attacker fitted against; it did not change the model's behaviour. It was not chosen as a control, nobody monitors it, the fleet is not uniform, and the next vendor update can revert it.

open as a page