Strong and Precise Modulation of Human Percepts via Robustified ANNs
Guy Gaziv, Michael J. Lee, James J. DiCarlo
摘要
The visual object category reports of artificial neural networks (ANNs) are notoriously sensitive to tiny, adversarial image perturbations. Because human category reports (aka human percepts) are thought to be insensitive to those same small-norm perturbations – and locally stable in general – this argues that ANNs are incomplete scientific models of human visual perception. Consistent with this, we show that when small-norm image perturbations are generated by standard ANN models, human object category percepts are indeed highly stable. However, in this very same “human-presumed-stable” regime, we find that robustified ANNs reliably discover low-norm image perturbations that strongly disrupt human percepts. These previously undetectable human perceptual disruptions are massive in amplitude, approaching the same level of sensitivity seen in robustified ANNs. Further, we show that robustified ANNs support precise perceptual state interventions : they guide the construction of low-norm image perturbations that strongly alter human category percepts toward specific prescribed percepts. In sum, these contemporary models of biological visual processing are now accurate enough to guide strong and precise interventions on human perception.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Stretching Beyond the Obvious: A Gradient-Free Framework to Unveil the Hidden Landscape of Visual InvarianceLorenzo Tausani, Paolo Muratore, Morgan Bruce Talbot, Giacomo Amerio 等ICLR 2026
- L-WISE: Boosting Human Visual Category Learning Through Model-Based Image Selection and EnhancementMorgan Bruce Talbot, Gabriel Kreiman, James J. DiCarlo, Guy GazivICLR 2025
它引用的顶会 Paper7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image PerturbationsJoel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger 等NeurIPS 2020 · 被引用 250 次
- Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial PerturbationsFlorian Tramèr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot 等ICML 2020 · 被引用 103 次
- Adversarially trained neural representations are already as robust as biological neural representationsChong Guo, Michael J. Lee, Guillaume Leclerc, Joel Dapello 等ICML 2022 · 被引用 31 次
相关 Paper
- Unadversarial Examples: Designing Objects for Robust VisionHadi Salman, Andrew Ilyas, Logan Engstrom, Sai Vemprala 等NeurIPS 2021 · 被引用 65 次
- Modeling Biological Immunity to Adversarial ExamplesEdward Kim, Jocelyn Rego, Yijing Watkins, Garrett T. KenyonCVPR 2020
- Attack to Explain Deep RepresentationMohammad A. A. K. Jalwana, Naveed Akhtar, Mohammed Bennamoun, Ajmal MianCVPR 2020
- Training on Foveated Images Improves Robustness to Adversarial AttacksMuhammad A. Shah, Aqsa Kashaf, Bhiksha RajNeurIPS 2023 · 被引用 9 次
- Preemptive Image Robustification for Protecting Users against Man-in-the-Middle Adversarial AttacksSeungyong Moon, Gaon An, Hyun Oh SongAAAI 2022 · 被引用 6 次
