Modeling Biological Immunity to Adversarial Examples
Edward Kim, Jocelyn Rego, Yijing Watkins, Garrett T. Kenyon
摘要
While deep learning continues to permeate through all fields of signal processing and machine learning, a critical exploit in these frameworks exists and remains unsolved. These exploits, or adversarial examples, are a type of signal attack that can change the output class of a classifier by perturbing the stimulus signal by an imperceptible amount. The attack takes advantage of statistical irregularities within the training data, where the added perturbations can "move" the image across deep learning decision boundaries. What is even more alarming is the transferability of these attacks to different deep learning models and architectures. This means a successful attack on one model has adversarial effects on other, unrelated models. In a general sense, adversarial attack through perturbations is not a machine learning vulnerability. Human and biological vision can also be fooled by various methods, i.e. mixing high and low frequency images together, by altering semantically related signals, or by sufficiently distorting the input signal. However, the amount and magnitude of such a distortion required to alter biological perception is at a much larger scale. In this work, we explored this gap through the lens of biology and neuroscience in order to understand the robustness exhibited in human perception. Our experiments show that by leveraging sparsity and modeling the biological mechanisms at a cellular level, we are able to mitigate the effect of adversarial alterations to the signal that have no perceptible meaning. Furthermore, we present and illustrate the effects of top-down functional processes that contribute to the inherent immunity in human perception in the context of exploiting these properties to make a more robust machine vision system.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Predify: Augmenting deep neural networks with brain-inspired predictive coding dynamicsBhavin Choksi, Milad Mozafari, Callum Biggs O'May, Benjamin Ador 等NeurIPS 2021 · 被引用 48 次
- LCANets: Lateral Competition Improves Robustness Against Corruption and AttackMichael A. Teti, Garrett T. Kenyon, Ben Migliori, Juston MooreICML 2022 · 被引用 22 次
它引用的顶会 Paper1
相关 Paper
- Attack to Explain Deep RepresentationMohammad A. A. K. Jalwana, Naveed Akhtar, Mohammed Bennamoun, Ajmal MianCVPR 2020
- Adversarially trained neural representations are already as robust as biological neural representationsChong Guo, Michael J. Lee, Guillaume Leclerc, Joel Dapello 等ICML 2022 · 被引用 31 次
- Strong and Precise Modulation of Human Percepts via Robustified ANNsGuy Gaziv, Michael J. Lee, James J. DiCarloNeurIPS 2023 · 被引用 12 次
- Phase-aware Adversarial Defense for Improving Adversarial RobustnessDawei Zhou, Nannan Wang, Heng Yang, Xinbo Gao 等ICML 2023 · 被引用 14 次
- Phase and Amplitude-aware Prompting for Enhancing Adversarial RobustnessYibo Xu, Dawei Zhou, Decheng Liu, Nannan WangICML 2025
