Skip to main content
QUICK REVIEW

[论文解读] Finding Biological Plausibility for Adversarially Robust Features via Metameric Tasks

Anne Harrington, Arturo Deza|arXiv (Cornell University)|Feb 2, 2022
Cell Image Analysis Techniques被引用 5
一句话总结

本文通过使用异构刺激辨别任务,研究了对抗性鲁棒深度神经网络(DNN)表征是否与人类外周视觉中的生物机制一致。研究发现,从鲁棒DNN生成的图像在视觉外周与原始图像在感知上无法区分——其表现与最先进的基于纹理的外周模型相当,表明对抗性鲁棒性可能源于与人类视觉中类似的局部纹理汇总统计特征。

ABSTRACT

Recent work suggests that representations learned by adversarially robust networks are more human perceptually-aligned than non-robust networks via image manipulations. Despite appearing closer to human visual perception, it is unclear if the constraints in robust DNN representations match biological constraints found in human vision. Human vision seems to rely on texture-based/summary statistic representations in the periphery, which have been shown to explain phenomena such as crowding and performance on visual search tasks. To understand how adversarially robust optimizations/representations compare to human vision, we performed a psychophysics experiment using a set of metameric discrimination tasks where we evaluated how well human observers could distinguish between images synthesized to match adversarially robust representations compared to non-robust representations and a texture synthesis model of peripheral vision (Texforms). We found that the discriminability of robust representation and texture model images decreased to near chance performance as stimuli were presented farther in the periphery. Moreover, performance on robust and texture-model images showed similar trends within participants, while performance on non-robust representations changed minimally across the visual field. These results together suggest that (1) adversarially robust representations capture peripheral computation better than non-robust representations and (2) robust representations capture peripheral computation similar to current state-of-the-art texture peripheral vision models. More broadly, our findings support the idea that localized texture summary statistic representations may drive human invariance to adversarial perturbations and that the incorporation of such representations in DNNs could give rise to useful properties like adversarial robustness.

研究动机与目标

  • 测试对抗性鲁棒DNN表征是否与人类外周视觉具有感知不变性。
  • 探究DNN中对抗性扰动的不变性是否源于与人类相似的低水平视觉计算。
  • 评估从鲁棒DNN生成的异构刺激在视网膜偏离度逐渐增加时是否在感知上与原始图像无法区分。
  • 比较对抗性训练DNN、非鲁棒DNN和基于纹理的外周模型(Texforms)在视觉场中不同位置的可辨别性。
  • 评估所观察到的感知趋势是否支持对抗性鲁棒性在深度学习中具有生物学基础。

提出的方法

  • 通过12名人类受试者参与的奇异性任务和2AFC匹配任务,开展心理物理学实验,评估合成刺激的感知可辨别性。
  • 从对抗性训练DNN、非鲁棒DNN和Texforms模型中合成图像,以匹配不同视觉处理层级的表征。
  • 在逐渐增大的视网膜偏离度(最高约30°)下呈现刺激,以模拟外周视觉并测量可辨别性趋势。
  • 采用“分析-合成”方法:若人类观察者无法区分合成图像与原始图像,则认为模型在感知上是异构的。
  • 应用异构辨别任务,比较不同刺激类型在视场偏离度函数下的感知表现。
  • 分析受试者内部的表现趋势,以评估鲁棒DNN与人类外周计算之间的相似性。

实验结果

研究问题

  • RQ1对抗性鲁棒DNN表征是否在视觉外周产生与原始图像在感知上无法区分的图像?
  • RQ2随着视网膜偏离度的增加,DNN合成图像的感知可辨别性如何变化?
  • RQ3对抗性鲁棒DNN的可辨别性趋势是否与人类外周视觉的已知模型(如Texforms)相似?
  • RQ4在视觉场中,鲁棒DNN与非鲁棒DNN生成的刺激在感知可辨别性上是否存在显著差异?
  • RQ5结果是否表明DNN中的对抗性鲁棒性可能源于与人类外周视觉相似的低水平纹理表征?

主要发现

  • 从对抗性鲁棒DNN合成的图像在偏离度超过30°时,可辨别性降至接近随机水平,表明其在视觉外周与原始图像具有极强的异构相似性。
  • 鲁棒DNN与Texforms模型的刺激在所有受试者中表现出高度相似的性能趋势,表明存在共享的感知不变性机制。
  • 相比之下,非鲁棒DNN生成的刺激在不同偏离度下可辨别性基本保持不变,表明其在外周无感知对齐。
  • 结果支持对抗性鲁棒表征捕捉了人类外周视觉计算的关键方面,尤其是局部纹理汇总统计特征。
  • 研究结果表明,对抗性鲁棒性可能通过中等水平视觉处理中的共享机制(如Texforms所建模的机制)与生物学合理性相关联。
  • 研究结果表明,DNN中的对抗性鲁棒性可能源于与人类外周视觉相似的不变性,尤其是在基于纹理的表征方面。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。