Test-set attack. Just keep feeding it natural inputs until it gets an error. As long as the system is not error-free this will succeed
Recently, this is what some researchers have tried. The paper is Natural Adversarial Examples, and the images are pretty interesting.
Recently, this is what some researchers have tried. The paper is Natural Adversarial Examples, and the images are pretty interesting.