It was discovered, with the advent of neural networks, that they are susceptible to bizarre "adversarial attacks." An adversary with access to the networks weights can seemingly find a small perturbation to the input image that forces the network to confidently make a wrong classification.  The initial understanding at the time was that it was a result of over-training. However, recent results have changed the common thinking to something more subtle. They imply something fundamental about the geometry of high-dimensional input spaces, and defending against such attacks yields networks that appear to "understand" basic features better and align more with our intuitions.