Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image Perturbations
Joel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger, David D. Cox, James J. DiCarlo
Abstract
Current state-of-the-art object recognition models are largely based on convolutional neural network (CNN) architectures, which are loosely inspired by the primate visual system. However, these CNNs can be fooled by imperceptibly small, explicitly crafted perturbations, and struggle to recognize objects in corrupted images that are easily recognized by humans. Here, by making comparisons with primate neural data, we first observed that CNN models with a neural hidden layer that better matches primate primary visual cortex (V1) are also more robust to adversarial attacks. Inspired by this observation, we developed VOneNets, a new class of hybrid CNN vision models. Each VOneNet contains a fixed weight neural network front-end that simulates primate V1, called the VOneBlock, followed by a neural network back-end adapted from current CNN vision models. The VOneBlock is based on a classical neuroscientific model of V1: the linear-nonlinear-Poisson model, consisting of a biologically-constrained Gabor filter bank, simple and complex cell nonlinearities, and a V1 neuronal stochasticity generator. After training, VOneNets retain high ImageNet performance, but each is substantially more robust, outperforming the base CNNs and state-of-the-art methods by 18% and 3%, respectively, on a conglomerate benchmark of perturbations comprised of white box adversarial attacks and common image corruptions. Finally, we show that all components of the VOneBlock work in synergy to improve robustness. While current CNN architectures are arguably brain-inspired, the results presented here demonstrate that more precisely mimicking just one stage of the primate visual system leads to new gains in ImageNet-level computer vision applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 989e4336-e7ce-4494-8e1e-39bbb5a940bbCited by top-tier papers39
- Partial success in closing the gap between human and machine visionRobert Geirhos, Kantharaju Narayanappa, Benjamin Mitzkus, Tizian Thieringer et al.NeurIPS 2021 · 304 citations
- Robust and Generalizable Visual Representation Learning via Random ConvolutionsZhenlin Xu, Deyi Liu, Junlin Yang, Colin Raffel et al.ICLR 2021 · 268 citations
- Towards robust vision by multi-task learning on monkey visual cortexShahd Safarani, Arne Nix, Konstantin Willeke, Santiago A. Cadena et al.NeurIPS 2021 · 67 citations
- NAS-OoD: Neural Architecture Search for Out-of-Distribution GeneralizationHaoyue Bai, Fengwei Zhou, Lanqing Hong, Nanyang Ye et al.ICCV 2021 · 46 citations
- Spatial-frequency channels, shape bias, and adversarial robustnessAjay Subramanian, Elena Sizikova, Najib J. Majaj, Denis G. PelliNeurIPS 2023 · 43 citations
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
Related papers
- Explicitly Modeling Subcortical Vision with a Neuro-Inspired Front-End Improves CNN RobustnessLucas Piper, Arlindo L. Oliveira, Tiago MarquesNeurIPS 2025 · 4 citations
- LCANets: Lateral Competition Improves Robustness Against Corruption and AttackMichael A. Teti, Garrett T. Kenyon, Ben Migliori, Juston MooreICML 2022 · 22 citations
- Neural Networks with Recurrent Generative FeedbackYujia Huang, James Gornet, Sihui Dai, Zhiding Yu et al.NeurIPS 2020 · 48 citations
- Explaining V1 Properties with a Biologically Constrained Deep Learning ArchitectureGalen Pogoncheff, Jacob Granley, Michael BeyelerNeurIPS 2023 · 17 citations
- Convolution Goes Higher-Order: A Biologically Inspired Mechanism Empowers Image ClassificationSimone Azeglio, Olivier Marre, Peter Neri, Ulisse FerrariNeurIPS 2025 · 5 citations
