Skip to main content
QUICK REVIEW

[论文解读] Neural Population Geometry Reveals the Role of Stochasticity in Robust Perception

Joel Dapello, Jenelle Feather|arXiv (Cornell University)|Nov 12, 2021
Adversarial Robustness in Machine Learning参考文献 9被引用 6
一句话总结

本文研究了神经种群几何结构如何揭示人工神经网络中的随机性——受生物神经可变性启发——在视觉和听觉领域均能增强对对抗性扰动的鲁棒性。通过高维神经表征的几何分析,作者表明,随机网络通过干净样本与对抗性样本表征的重叠实现鲁棒性,这种重叠由对抗性性能与干净性能之间的权衡所介导。

ABSTRACT

Adversarial examples are often cited by neuroscientists and machine learning researchers as an example of how computational models diverge from biological sensory systems. Recent work has proposed adding biologically-inspired components to visual neural networks as a way to improve their adversarial robustness. One surprisingly effective component for reducing adversarial vulnerability is response stochasticity, like that exhibited by biological neurons. Here, using recently developed geometrical techniques from computational neuroscience, we investigate how adversarial perturbations influence the internal representations of standard, adversarially trained, and biologically-inspired stochastic networks. We find distinct geometric signatures for each type of network, revealing different mechanisms for achieving robust representations. Next, we generalize these results to the auditory domain, showing that neural stochasticity also makes auditory models more robust to adversarial perturbations. Geometric analysis of the stochastic networks reveals overlap between representations of clean and adversarially perturbed stimuli, and quantitatively demonstrates that competing geometric effects of stochasticity mediate a tradeoff between adversarial and clean performance. Our results shed light on the strategies of robust perception utilized by adversarially trained and stochastic networks, and help explain how stochasticity may be beneficial to machine and biological computation.

研究动机与目标

  • 理解生物启发随机性如何提升人工神经网络的对抗鲁棒性。
  • 比较标准网络、对抗训练网络与随机网络在面对干净与对抗性刺激时的几何特征。
  • 探究随机性的优势是否可扩展至听觉感知模型,而不仅限于视觉领域。
  • 量化由随机表征引发的干净性能与对抗鲁棒性之间的权衡。
  • 探索神经种群几何结构如何在人工与生物系统中介导鲁棒感知。

提出的方法

  • 应用计算神经科学中的流形分析技术,研究深度网络中高维神经表征的特性。
  • 在视觉与听觉领域训练并分析三类网络:标准网络、对抗训练网络与生物启发随机网络。
  • 使用流形宽度、可分性与内在维度等几何度量,比较干净与对抗性刺激表征的差异。
  • 在表征上训练二分类SVM,以评估在不同噪声水平下,干净与对抗性样本流形的线性可分性。
  • 系统性地改变网络输出的高斯噪声水平,以绘制性能权衡与几何效应的关系。
  • 将发现扩展至一种新型听觉模型——StochCochResNet50,其具有随机响应,证实了跨模态的泛化性。

实验结果

研究问题

  • RQ1在面对干净与对抗性刺激时,标准网络、对抗训练网络与随机网络的神经种群表征几何特征有何不同?
  • RQ2神经随机性是否在听觉神经网络中提升对抗鲁棒性,与在视觉模型中的效果类似?
  • RQ3干净与对抗性刺激表征之间的重叠在随机网络中如何促进鲁棒感知?
  • RQ4在几何层面上,随机性如何介导干净性能与对抗鲁棒性之间的权衡?
  • RQ5随机网络中鲁棒性的几何机制是否与对抗训练网络相似?

主要发现

  • 随机网络在神经种群表征中表现出独特的几何特征,其特征为干净与对抗性刺激流形之间的重叠显著增加。
  • 随着噪声水平升高,尤其是高噪声区域,干净与对抗性表征的重叠程度增加,表明存在一种保护性几何机制。
  • 随着随机性增强,通过在表征上训练的二分类SVM显示,干净与对抗性样本流形的线性可分性降低。
  • 对抗鲁棒性与干净性能之间存在权衡:更高的随机性可提升鲁棒性,但因类别流形纠缠加剧而降低峰值准确率。
  • 在听觉模型StochCochResNet50中,随机性的优势得到验证,其增强了鲁棒性并产生了与视觉模型一致的几何模式,证实了其泛化能力。
  • 流形宽度随噪声水平增加,而类别与样本流形容量均下降,表明随机性导致表征空间发生结构性重组。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。