Simulating a Primary Visual Cortex at the Front of CNNs Improves Robustness to Image Perturbations
Joel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger, David D. Cox, James J. DiCarlo
摘要
Current state-of-the-art object recognition models are largely based on convolutional neural network (CNN) architectures, which are loosely inspired by the primate visual system. However, these CNNs can be fooled by imperceptibly small, explicitly crafted perturbations, and struggle to recognize objects in corrupted images that are easily recognized by humans. Here, by making comparisons with primate neural data, we first observed that CNN models with a neural hidden layer that better matches primate primary visual cortex (V1) are also more robust to adversarial attacks. Inspired by this observation, we developed VOneNets, a new class of hybrid CNN vision models. Each VOneNet contains a fixed weight neural network front-end that simulates primate V1, called the VOneBlock, followed by a neural network back-end adapted from current CNN vision models. The VOneBlock is based on a classical neuroscientific model of V1: the linear-nonlinear-Poisson model, consisting of a biologically-constrained Gabor filter bank, simple and complex cell nonlinearities, and a V1 neuronal stochasticity generator. After training, VOneNets retain high ImageNet performance, but each is substantially more robust, outperforming the base CNNs and state-of-the-art methods by 18% and 3%, respectively, on a conglomerate benchmark of perturbations comprised of white box adversarial attacks and common image corruptions. Finally, we show that all components of the VOneBlock work in synergy to improve robustness. While current CNN architectures are arguably brain-inspired, the results presented here demonstrate that more precisely mimicking just one stage of the primate visual system leads to new gains in ImageNet-level computer vision applications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper39
- Partial success in closing the gap between human and machine visionRobert Geirhos, Kantharaju Narayanappa, Benjamin Mitzkus, Tizian Thieringer 等NeurIPS 2021 · 被引用 304 次
- Robust and Generalizable Visual Representation Learning via Random ConvolutionsZhenlin Xu, Deyi Liu, Junlin Yang, Colin Raffel 等ICLR 2021 · 被引用 268 次
- Towards robust vision by multi-task learning on monkey visual cortexShahd Safarani, Arne Nix, Konstantin Willeke, Santiago A. Cadena 等NeurIPS 2021 · 被引用 67 次
- NAS-OoD: Neural Architecture Search for Out-of-Distribution GeneralizationHaoyue Bai, Fengwei Zhou, Lanqing Hong, Nanyang Ye 等ICCV 2021 · 被引用 46 次
- Spatial-frequency channels, shape bias, and adversarial robustnessAjay Subramanian, Elena Sizikova, Najib J. Majaj, Denis G. PelliNeurIPS 2023 · 被引用 43 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph 等ICLR 2020 · 被引用 1,572 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
相关 Paper
- Explicitly Modeling Subcortical Vision with a Neuro-Inspired Front-End Improves CNN RobustnessLucas Piper, Arlindo L. Oliveira, Tiago MarquesNeurIPS 2025 · 被引用 4 次
- LCANets: Lateral Competition Improves Robustness Against Corruption and AttackMichael A. Teti, Garrett T. Kenyon, Ben Migliori, Juston MooreICML 2022 · 被引用 22 次
- Neural Networks with Recurrent Generative FeedbackYujia Huang, James Gornet, Sihui Dai, Zhiding Yu 等NeurIPS 2020 · 被引用 48 次
- Explaining V1 Properties with a Biologically Constrained Deep Learning ArchitectureGalen Pogoncheff, Jacob Granley, Michael BeyelerNeurIPS 2023 · 被引用 17 次
- Convolution Goes Higher-Order: A Biologically Inspired Mechanism Empowers Image ClassificationSimone Azeglio, Olivier Marre, Peter Neri, Ulisse FerrariNeurIPS 2025 · 被引用 5 次
