Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency Domain
Yiting Chen, Qibing Ren, Junchi Yan
摘要
The existence of adversarial examples poses concerns for the robustness of convolutional neural networks (CNN), for which a popular hypothesis is about the frequency bias phenomenon: CNNs rely more on high-frequency components (HFC) for classification than humans, which causes the brittleness of CNNs. However, most previous works manually select and roughly divide the image frequency spectrum and conduct qualitative analysis. In this work, we introduce Shapley value, a metric of cooperative game theory, into the frequency domain and propose to quantify the positive (negative) impact of every frequency component of data on CNNs. Based on the Shapley value, we quantify the impact in a fine-grained way and show intriguing instance disparity. Statistically, we investigate adversarial training(AT) and the adversarial attack in the frequency domain. The observations motivate us to perform an in-depth analysis and lead to multiple novel hypotheses about i) the cause of adversarial robustness of the AT model; ii) the fairness problem of AT between different classes in the same dataset; iii) the attack bias on different frequency components. Finally, we propose a Shapley-value guided data augmentation technique for improving the robustness. Experimental results on image classification benchmarks show its effectiveness. The code for this paper is at https://github.com/Ytchen981/CSA
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- HiLo: Detailed and Robust 3D Clothed Human Reconstruction with High-and Low-Frequency Information of Parametric ModelsYifan Yang, Dong Liu, Shuhai Zhang, Zeshuai Deng 等CVPR 2024 · 被引用 11 次
- Revisiting Visual Model Robustness: A Frequency Long-Tailed Distribution ViewZhiyu Lin, Yifei Gao, Yunfan Yang, Jitao SangNeurIPS 2023 · 被引用 7 次
- Salient Frequency-aware Exemplar Compression for Resource-constrained Online Continual LearningJunsu Kim, Suhyun KimAAAI 2025 · 被引用 1 次
- Low-Cost Hard-Label Adversarial Attack with Theoretical FoundationsJun Liu, Leo Yu Zhang, Fengpeng Li, Isao Echizen 等USENIX Security 2026
- One Wave To Explain Them All: A Unifying Perspective On Feature AttributionGabriel Kasmi, Amandine Brunetto, Thomas Fel, Jayneel ParekhICML 2025
它引用的顶会 Paper17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- The Many Shapley Values for Model ExplanationMukund Sundararajan, Amir NajmiICML 2020 · 被引用 799 次
- Problems with Shapley-value-based explanations as feature importance measuresI. Elizabeth Kumar, Suresh Venkatasubramanian, Carlos Scheidegger, Sorelle A. FriedlerICML 2020 · 被引用 458 次
相关 Paper
- HybridAugment++: Unified Frequency Spectra Perturbations for Model RobustnessMehmet Kerim Yucel, Ramazan Gokberk Cinbis, Pinar DuyguluICCV 2023 · 被引用 16 次
- Interpreting Attributions and Interactions of Adversarial AttacksXin Wang, Shuyun Lin, Hao Zhang, Yufei Zhu 等ICCV 2021 · 被引用 20 次
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
- Amplitude-Phase Recombination: Rethinking Robustness of Convolutional Neural Networks in Frequency DomainGuangyao Chen, Peixi Peng, Li Ma, Jia Li 等ICCV 2021 · 被引用 132 次
- DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency DomainFengpeng Li, Kemou Li, Haiwei Wu, Jinyu Tian 等NeurIPS 2024 · 被引用 19 次
