Skip to main content
QUICK REVIEW

[论文解读] Robustified ANNs Reveal Wormholes Between Human Category Percepts

Guy Gaziv, Michael J. Lee|arXiv (Cornell University)|Aug 14, 2023
Neural dynamics and brain functionNeuroscience被引用 3
一句话总结

本研究表明,经过鲁棒化处理的人工神经网络(ANN)能够识别出显著改变人类物体类别感知的低范数图像扰动——这挑战了人类感知在这些扰动下具有稳定性的假设。这些扰动在图像空间中充当连接语义上不同的感知状态的‘虫洞’,揭示了人类视觉处理中此前未被发现的漏洞,而这些漏洞可借助最先进的ANN模型进行预测。

ABSTRACT

The visual object category reports of artificial neural networks (ANNs) are notoriously sensitive to tiny, adversarial image perturbations. Because human category reports (aka human percepts) are thought to be insensitive to those same small-norm perturbations -- and locally stable in general -- this argues that ANNs are incomplete scientific models of human visual perception. Consistent with this, we show that when small-norm image perturbations are generated by standard ANN models, human object category percepts are indeed highly stable. However, in this very same "human-presumed-stable" regime, we find that robustified ANNs reliably discover low-norm image perturbations that strongly disrupt human percepts. These previously undetectable human perceptual disruptions are massive in amplitude, approaching the same level of sensitivity seen in robustified ANNs. Further, we show that robustified ANNs support precise perceptual state interventions: they guide the construction of low-norm image perturbations that strongly alter human category percepts toward specific prescribed percepts. These observations suggest that for arbitrary starting points in image space, there exists a set of nearby "wormholes", each leading the subject from their current category perceptual state into a semantically very different state. Moreover, contemporary ANN models of biological visual processing are now accurate enough to consistently guide us to those portals.

研究动机与目标

  • 挑战主流假设,即人类物体类别感知对低范数图像扰动具有鲁棒性。
  • 研究鲁棒化ANN是否能揭示标准模型无法检测到的人类感知干扰。
  • 确定在感知被认为稳定的低像素预算范围内,是否可对人类感知进行精确、有针对性的调制。
  • 评估当代灵长类腹侧流ANN模型是否能准确引导发现这些感知‘虫洞’。

提出的方法

  • 通过ℓ₂-范数约束训练对基于ResNet50的ANN进行对抗鲁棒化,以增强其对微小扰动的抵抗能力。
  • 利用鲁棒化ANN潜在空间中的基于梯度的优化方法生成低范数图像扰动,以实现特定类别转移。
  • 使用‘代理’模型模拟类人分类行为,并验证感知干扰效应。
  • 在119名受试者中收集对扰动图像的感知报告,以测量类别转移率和失效率。
  • 应用失效率校正方法,估算零失效率条件下的感知行为,提升感知对齐度量的可靠性。
  • 系统比较普通ANN与鲁棒化ANN在低范数扰动(≤30 ℓ₂-范数)下预测人类感知转移的能力。
Figure 1: Robustified models discover low-norm image perturbations that strongly modulate human category percepts. The prevailing assumption: Human object category percepts have complicated topology in pixel space, but are robust (i.e., stable) inside a low pixel budget envelope around most natural
Figure 1: Robustified models discover low-norm image perturbations that strongly modulate human category percepts. The prevailing assumption: Human object category percepts have complicated topology in pixel space, but are robust (i.e., stable) inside a low pixel budget envelope around most natural

实验结果

研究问题

  • RQ1在低范数扰动范围内,鲁棒化ANN是否缩小了人工与人类感知之间的行为对齐差距?
  • RQ2由鲁棒化ANN生成的低范数图像扰动是否能引发人类物体类别感知的强烈且可靠变化?
  • RQ3在整个图像空间中,是否存在‘虫洞’——即从一个感知状态到语义上相距遥远的另一感知状态的邻近扰动?
  • RQ4鲁棒化ANN是否能精确地针对并调制人类感知朝向任意预设类别?

主要发现

  • 鲁棒化ANN发现了≤30 ℓ₂-范数的低范数图像扰动,使人类观察者在类别感知上出现干扰的比率高达约90%,挑战了感知鲁棒性的假设。
  • 当扰动由鲁棒化ANN引导时,人类感知反应表现出强烈且有针对性的调制,向特定类别偏移,多目标调制任务中的干扰率约为60%。
  • 普通ANN与人类之间的行为对齐差距较大,但鲁棒化ANN显著缩小了这一差距,尤其是在低像素预算范围内。
  • 鲁棒化ANN实现了精确的低范数干预,能够可靠地将人类感知从一个类别切换到另一个类别,表明感知空间中存在‘虫洞’。
  • 结果表明,当代灵长类腹侧流ANN模型的准确性足以持续引导发现这些感知门户。
  • 尽管对齐程度较强,但仍存在残余的行为差距,表明即使鲁棒化ANN也可能未能完全捕捉人类视觉处理的所有方面。
Figure 2: Low-norm image perturbations discovered by robustified models strongly disrupt human category judgements. (a) The Guide Models used for Disruption Modulation (DM) image generation. (b) Disruption rates of humans and models. All panels share the same set of start images, and the four sets o
Figure 2: Low-norm image perturbations discovered by robustified models strongly disrupt human category judgements. (a) The Guide Models used for Disruption Modulation (DM) image generation. (b) Disruption rates of humans and models. All panels share the same set of start images, and the four sets o

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。