AI History Battle
The pixel you cannot see classification

It is 2013, and a disquieting discovery is circulating: a deep network that classifies images with superhuman confidence can be flipped to a wildly wrong label by a perturbation so small no human eye can detect it. The image looks identical; the model calls a school bus an ostrich. Characterize why high-accuracy classifiers are so brittle at these engineered points, and build defenses that hold when an adversary — not nature — chooses the input. The stakes leave the lab immediately: a stop sign with a few stickers, a face-recognition gate, a malware detector. Get it wrong and you deploy a system whose benchmark accuracy is a fiction the moment someone wants it to fail — and in security, someone always does.

adversarialpredictrobustness
b. 1928
tapped
5

Chomsky's formal grammars and career-long critique of purely statistical approaches to language have essentially no technical connection to adversarial examples, gradient-based attacks, or deep network robustness in vision. His research domain, formal language theory, is a different subject and methodology entirely from the pixel-level perturbation vulnerability this problem describes. His skepticism of purely statistical, pattern-matching methods is, if anything, thematically resonant with critiques of deep learning's brittleness, but he never engaged with adversarial machine learning technically. His relevance to this specific 2013-era problem is essentially nil beyond a loose, largely coincidental philosophical resonance. The resonance is philosophical opposition, not a technical contribution. The two research programs remain, by design, entirely disconnected from each other.

b. 1933
was tapped
8

Hopfield's energy-based associative memory networks, for which he shared the 2024 Nobel Prize in Physics, solve pattern completion through recurrent dynamics settling into stable attractor states, a different architecture and failure mode from the feedforward convolutional classifiers this problem describes as vulnerable to adversarial perturbation. His networks have their own documented sensitivities to input noise, giving a thin structural resemblance to this problem's broader theme of neural network fragility, but he never worked on adversarial examples in the specific 2013 sense this problem describes. His relevance to this specific problem is essentially nil beyond broad, diffuse membership in the neural network tradition generally. Attractor dynamics fail by a different mechanism than gradient-based perturbation.

Head to head 01 over 1 battle
Read Chomsky Read Hopfield Leaderboard

Battle #102 · 8/10/2026, 11:37:57 AM · this result is deterministic: the same two personas on this problem always resolve the same way.