Finding Biological Plausibility for Adversarially Robust Features via Metameric Tasks
Anne Harrington, Arturo Deza
摘要
Recent work suggests that feature constraints in the training datasets of deep neural networks (DNNs) drive robustness to adversarial noise (Ilyas et al., 2019) . The representations learned by such adversarially robust networks have also been shown to be more human perceptually-aligned than non-robust networks via image manipulations (Santurkar et al., 2019; Engstrom et al., 2019) . Despite appearing closer to human visual perception, it is unclear if the constraints in robust DNN representations match biological constraints found in human vision. Human vision seems to rely on texture-based/summary statistic representations in the periphery, which have been shown to explain phenomena such as crowding (Balas et al., 2009) and performance on visual search tasks (Rosenholtz et al., 2012) . To understand how adversarially robust optimizations/representations compare to human vision, we performed a psychophysics experiment using a metamer task similar to Freeman & Simoncelli ( 2011 ); Wallis et al. (2019); Deza et al. (2019b) where we evaluated how well human observers could distinguish between images synthesized to match adversarially robust representations compared to nonrobust representations and a texture synthesis model of peripheral vision (Texforms (Long et al., 2018) ). We found that the discriminability of robust representation and texture model images decreased to near chance performance as stimuli were presented farther in the periphery. Moreover, performance on robust and texture-model images showed similar trends within participants, while performance on non-robust representations changed minimally across the visual field. These results together suggest that (1) adversarially robust representations capture peripheral computation better than non-robust representations and (2) robust representations capture peripheral computation similar to current state-of-the-art texture peripheral vision models. More broadly, our findings support the idea that localized texture summary statistic representations may drive human invariance to adversarial perturbations and that the incorporation of such representations in DNNs could give rise to useful properties like adversarial robustness. Link to
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Peripheral Vision TransformerJuhong Min, Yucheng Zhao, Chong Luo, Minsu ChoNeurIPS 2022 · 被引用 49 次
- Adversarial Robustness Limits via Scaling-Law and Human-Alignment StudiesBrian R. Bartoldson, James Diffenderfer, Konstantinos Parasyris, Bhavya KailkhuraICML 2024 · 被引用 45 次
- A Dual-Stream Neural Network Explains the Functional Segregation of Dorsal and Ventral Visual Pathways in Human BrainsMinkyu Choi, Kuan Han, Xiaokai Wang, Yizhen Zhang 等NeurIPS 2023 · 被引用 33 次
- Strong and Precise Modulation of Human Percepts via Robustified ANNsGuy Gaziv, Michael J. Lee, James J. DiCarloNeurIPS 2023 · 被引用 12 次
- Improved Efficiency Based on Learned Saccade and Continuous Scene Reconstruction From Foveated Visual SamplingJiayang Liu, Yiming Bu, Daniel Tso, Qinru QiuICLR 2024 · 被引用 9 次
它引用的顶会 Paper4
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg 等NeurIPS 2021 · 被引用 384 次
- Partial success in closing the gap between human and machine visionRobert Geirhos, Kantharaju Narayanappa, Benjamin Mitzkus, Tizian Thieringer 等NeurIPS 2021 · 被引用 304 次
- Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image PerturbationsJoel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger 等NeurIPS 2020 · 被引用 250 次
- Biologically Inspired Mechanisms for Adversarial RobustnessManish V. Reddy, Andrzej Banburski, Nishka Pant, Tomaso A. PoggioNeurIPS 2020 · 被引用 53 次
相关 Paper
- COCO-Periph: Bridging the Gap Between Human and Machine Perception in the PeripheryAnne Harrington, Vasha DuTell, Mark Hamilton, Ayush Tewari 等ICLR 2024 · 被引用 6 次
- Training on Foveated Images Improves Robustness to Adversarial AttacksMuhammad A. Shah, Aqsa Kashaf, Bhiksha RajNeurIPS 2023 · 被引用 9 次
- Exploring perceptual straightness in learned visual representationsAnne Harrington, Vasha DuTell, Ayush Tewari, Mark Hamilton 等ICLR 2023
- Interpreting Robustness Proofs of Deep Neural NetworksDebangshu Banerjee, Avaljot Singh, Gagandeep SinghICLR 2024 · 被引用 6 次
- Hold me tight! Influence of discriminative features on deep network boundariesGuillermo Ortiz-Jiménez, Apostolos Modas, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardNeurIPS 2020 · 被引用 53 次
