How did it trick the AI into thinking the squirrel was a goldfish ? It had to optimize toward a goal of matching data from that which the AI had already classified as goldfish worthy ? Or ? Confusing
I would guess, by computing a gradient in the goldfish direction, then backpropagating, then updating parameters on the water ripples, to create distortions that push the classifier in the goldfish direction. If that makes sense...