Strong and Precise Modulation of Human Percepts via Robustified ANNs
Guy Gaziv, Michael J. Lee, James J. DiCarlo
Abstract
The visual object category reports of artificial neural networks (ANNs) are notoriously sensitive to tiny, adversarial image perturbations. Because human category reports (aka human percepts) are thought to be insensitive to those same small-norm perturbations – and locally stable in general – this argues that ANNs are incomplete scientific models of human visual perception. Consistent with this, we show that when small-norm image perturbations are generated by standard ANN models, human object category percepts are indeed highly stable. However, in this very same “human-presumed-stable” regime, we find that robustified ANNs reliably discover low-norm image perturbations that strongly disrupt human percepts. These previously undetectable human perceptual disruptions are massive in amplitude, approaching the same level of sensitivity seen in robustified ANNs. Further, we show that robustified ANNs support precise perceptual state interventions : they guide the construction of low-norm image perturbations that strongly alter human category percepts toward specific prescribed percepts. In sum, these contemporary models of biological visual processing are now accurate enough to guide strong and precise interventions on human perception.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0f8941bb-309c-4660-8492-1d4e14f3997bCited by top-tier papers2
- Stretching Beyond the Obvious: A Gradient-Free Framework to Unveil the Hidden Landscape of Visual InvarianceLorenzo Tausani, Paolo Muratore, Morgan Bruce Talbot, Giacomo Amerio et al.ICLR 2026
- L-WISE: Boosting Human Visual Category Learning Through Model-Based Image Selection and EnhancementMorgan Bruce Talbot, Gabriel Kreiman, James J. DiCarlo, Guy GazivICLR 2025
Builds on7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image PerturbationsJoel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger et al.NeurIPS 2020 · 250 citations
- Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial PerturbationsFlorian Tramèr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot et al.ICML 2020 · 103 citations
- Adversarially trained neural representations are already as robust as biological neural representationsChong Guo, Michael J. Lee, Guillaume Leclerc, Joel Dapello et al.ICML 2022 · 31 citations
Related papers
- Unadversarial Examples: Designing Objects for Robust VisionHadi Salman, Andrew Ilyas, Logan Engstrom, Sai Vemprala et al.NeurIPS 2021 · 65 citations
- Modeling Biological Immunity to Adversarial ExamplesEdward Kim, Jocelyn Rego, Yijing Watkins, Garrett T. KenyonCVPR 2020
- Attack to Explain Deep RepresentationMohammad A. A. K. Jalwana, Naveed Akhtar, Mohammed Bennamoun, Ajmal MianCVPR 2020
- Training on Foveated Images Improves Robustness to Adversarial AttacksMuhammad A. Shah, Aqsa Kashaf, Bhiksha RajNeurIPS 2023 · 9 citations
- Preemptive Image Robustification for Protecting Users against Man-in-the-Middle Adversarial AttacksSeungyong Moon, Gaon An, Hyun Oh SongAAAI 2022 · 6 citations
