Training on Foveated Images Improves Robustness to Adversarial Attacks
Muhammad A. Shah, Aqsa Kashaf, Bhiksha Raj
Abstract
Deep neural networks (DNNs) have been shown to be vulnerable to adversarial attacks -- subtle, perceptually indistinguishable perturbations of inputs that change the response of the model. In the context of vision, we hypothesize that an important contributor to the robustness of human visual perception is constant exposure to low-fidelity visual stimuli in our peripheral vision. To investigate this hypothesis, we develop , an image transform that simulates the loss in fidelity of peripheral vision by blurring the image and reducing its color saturation based on the distance from a given fixation point. We show that compared to DNNs trained on the original images, DNNs trained on images transformed by are substantially more robust to adversarial attacks, as well as other, non-adversarial, corruptions, achieving up to 25% higher accuracy on perturbed data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 53b411ec-808f-4692-93b2-7c4e90935d11Builds on10
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- MLP-Mixer: An all-MLP Architecture for VisionIlya O. Tolstikhin, Neil Houlsby, Alexander Kolesnikov, Lucas Beyer et al.NeurIPS 2021 · 3,862 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg et al.NeurIPS 2021 · 427 citations
Related papers
- Finding Biological Plausibility for Adversarially Robust Features via Metameric TasksAnne Harrington, Arturo DezaICLR 2022 · 23 citations
- COCO-Periph: Bridging the Gap Between Human and Machine Perception in the PeripheryAnne Harrington, Vasha DuTell, Mark Hamilton, Ayush Tewari et al.ICLR 2024 · 6 citations
- Strong and Precise Modulation of Human Percepts via Robustified ANNsGuy Gaziv, Michael J. Lee, James J. DiCarloNeurIPS 2023 · 12 citations
- Modeling Biological Immunity to Adversarial ExamplesEdward Kim, Jocelyn Rego, Yijing Watkins, Garrett T. KenyonCVPR 2020
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
