Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency Domain
Yiting Chen, Qibing Ren, Junchi Yan
Abstract
The existence of adversarial examples poses concerns for the robustness of convolutional neural networks (CNN), for which a popular hypothesis is about the frequency bias phenomenon: CNNs rely more on high-frequency components (HFC) for classification than humans, which causes the brittleness of CNNs. However, most previous works manually select and roughly divide the image frequency spectrum and conduct qualitative analysis. In this work, we introduce Shapley value, a metric of cooperative game theory, into the frequency domain and propose to quantify the positive (negative) impact of every frequency component of data on CNNs. Based on the Shapley value, we quantify the impact in a fine-grained way and show intriguing instance disparity. Statistically, we investigate adversarial training(AT) and the adversarial attack in the frequency domain. The observations motivate us to perform an in-depth analysis and lead to multiple novel hypotheses about i) the cause of adversarial robustness of the AT model; ii) the fairness problem of AT between different classes in the same dataset; iii) the attack bias on different frequency components. Finally, we propose a Shapley-value guided data augmentation technique for improving the robustness. Experimental results on image classification benchmarks show its effectiveness. The code for this paper is at https://github.com/Ytchen981/CSA
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db76f36e-2594-4475-9635-4fdbd62bd045Cited by top-tier papers6
- HiLo: Detailed and Robust 3D Clothed Human Reconstruction with High-and Low-Frequency Information of Parametric ModelsYifan Yang, Dong Liu, Shuhai Zhang, Zeshuai Deng et al.CVPR 2024 · 11 citations
- Revisiting Visual Model Robustness: A Frequency Long-Tailed Distribution ViewZhiyu Lin, Yifei Gao, Yunfan Yang, Jitao SangNeurIPS 2023 · 7 citations
- Salient Frequency-aware Exemplar Compression for Resource-constrained Online Continual LearningJunsu Kim, Suhyun KimAAAI 2025 · 1 citation
- Low-Cost Hard-Label Adversarial Attack with Theoretical FoundationsJun Liu, Leo Yu Zhang, Fengpeng Li, Isao Echizen et al.USENIX Security 2026
- One Wave To Explain Them All: A Unifying Perspective On Feature AttributionGabriel Kasmi, Amandine Brunetto, Thomas Fel, Jayneel ParekhICML 2025
Builds on17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- The Many Shapley Values for Model ExplanationMukund Sundararajan, Amir NajmiICML 2020 · 799 citations
- Problems with Shapley-value-based explanations as feature importance measuresI. Elizabeth Kumar, Suresh Venkatasubramanian, Carlos Scheidegger, Sorelle A. FriedlerICML 2020 · 458 citations
Related papers
- HybridAugment++: Unified Frequency Spectra Perturbations for Model RobustnessMehmet Kerim Yucel, Ramazan Gokberk Cinbis, Pinar DuyguluICCV 2023 · 16 citations
- Interpreting Attributions and Interactions of Adversarial AttacksXin Wang, Shuyun Lin, Hao Zhang, Yufei Zhu et al.ICCV 2021 · 20 citations
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
- Amplitude-Phase Recombination: Rethinking Robustness of Convolutional Neural Networks in Frequency DomainGuangyao Chen, Peixi Peng, Li Ma, Jia Li et al.ICCV 2021 · 132 citations
- DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency DomainFengpeng Li, Kemou Li, Haiwei Wu, Jinyu Tian et al.NeurIPS 2024 · 19 citations
