Biologically Inspired Mechanisms for Adversarial Robustness
Manish V. Reddy, Andrzej Banburski, Nishka Pant, Tomaso A. Poggio
Abstract
A convolutional neural network strongly robust to adversarial perturbations at reasonable computational and performance cost has not yet been demonstrated. The primate visual ventral stream seems to be robust to small perturbations in visual stimuli but the underlying mechanisms that give rise to this robust perception are not understood. In this work, we investigate the role of two biologically plausible mechanisms in adversarial robustness. We demonstrate that the nonuniform sampling performed by the primate retina and the presence of multiple receptive fields with a range of receptive field sizes at each eccentricity improve the robustness of neural networks to small adversarial perturbations. We verify that these two mechanisms do not suffer from gradient obfuscation and study their contribution to adversarial robustness through ablation studies. Preprint. Under review.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5c39f33f-5f7c-44f4-9d64-799670a645aeCited by top-tier papers10
- Peripheral Vision TransformerJuhong Min, Yucheng Zhao, Chong Luo, Minsu ChoNeurIPS 2022 · 49 citations
- A Dual-Stream Neural Network Explains the Functional Segregation of Dorsal and Ventral Visual Pathways in Human BrainsMinkyu Choi, Kuan Han, Xiaokai Wang, Yizhen Zhang et al.NeurIPS 2023 · 33 citations
- Finding Biological Plausibility for Adversarially Robust Features via Metameric TasksAnne Harrington, Arturo DezaICLR 2022 · 23 citations
- Explaining V1 Properties with a Biologically Constrained Deep Learning ArchitectureGalen Pogoncheff, Jacob Granley, Michael BeyelerNeurIPS 2023 · 17 citations
- Improved Efficiency Based on Learned Saccade and Continuous Scene Reconstruction From Foveated Visual SamplingJiayang Liu, Yiming Bu, Daniel Tso, Qinru QiuICLR 2024 · 9 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Towards Large Yet Imperceptible Adversarial Image Perturbations With Perceptual Color DistanceZhengyu Zhao, Zhuoran Liu, Martha A. LarsonCVPR 2020
Related papers
- Adversarially trained neural representations are already as robust as biological neural representationsChong Guo, Michael J. Lee, Guillaume Leclerc, Joel Dapello et al.ICML 2022 · 31 citations
- Training on Foveated Images Improves Robustness to Adversarial AttacksMuhammad A. Shah, Aqsa Kashaf, Bhiksha RajNeurIPS 2023 · 9 citations
- Neural Networks with Recurrent Generative FeedbackYujia Huang, James Gornet, Sihui Dai, Zhiding Yu et al.NeurIPS 2020 · 48 citations
- Modeling Biological Immunity to Adversarial ExamplesEdward Kim, Jocelyn Rego, Yijing Watkins, Garrett T. KenyonCVPR 2020
- Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image PerturbationsJoel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger et al.NeurIPS 2020 · 250 citations
