This is obviously vulnerable to adversarial examples or extreme OOD settings, but then robustness seems to be increasing with compute used, and we can do a decent job of OOD-catching.
This seems like the crux of the matter. I don’t think OOD or robustness is as straightforward as you think.
This seems like the crux of the matter. I don’t think OOD or robustness is as straightforward as you think.
remind me what OOD stands for again?
Out of distribution