Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry
Although deep neural networks (DNNs) achieve excellent performance and even outperform humans on various computer vision tasks, the robustness of DNNs to small perturbations is still far from being comparable to the human visual system. Indeed, adversarial attacks, which are very small worst-case pe...
Main Author: | |
---|---|
Other Authors: | |
Format: | Thesis |
Published: |
Massachusetts Institute of Technology
2022
|
Online Access: | https://hdl.handle.net/1721.1/139227 |
_version_ | 1826211198338596864 |
---|---|
author | Le Thi Nguyet, Hang |
author2 | DiCarlo, James |
author_facet | DiCarlo, James Le Thi Nguyet, Hang |
author_sort | Le Thi Nguyet, Hang |
collection | MIT |
description | Although deep neural networks (DNNs) achieve excellent performance and even outperform humans on various computer vision tasks, the robustness of DNNs to small perturbations is still far from being comparable to the human visual system. Indeed, adversarial attacks, which are very small worst-case perturbations, can reduce the accuracy of state-of-the-art models dramatically to close to random chance while remaining humanly indistinguishable. Since the human visual system has a high tolerance to small input perturbations, Dapello et al developed VOneNet, a model with architecture similar to the V1 brain area as the front-end and standard DNNs architecture as the back-end, and demonstrated that VOneNet has significantly better adversarial robustness than the standard ResNet.
In this work, we analyze the internal representations of adversarial examples to dissect how adversarial perturbations alter the geometric structure and encoded information of the representations and to understand how brain-like components such as representational noise and neural normalization can help to improve adversarial robustness. Firstly, we show that internal representations from adversarial examples are linearly separated and still encode a significant amount of class information. Secondly, we demonstrate that representational noise can create an overlap between noise-injected clean and adversarial examples, therefore improving the robustness of the model. Finally, we show that neural normalization, which is based on divisive normalization and lateral inhibition, achieves better adversarial performance compared to traditional normalization methods such as batch normalization, which is based on standardization. |
first_indexed | 2024-09-23T15:02:08Z |
format | Thesis |
id | mit-1721.1/139227 |
institution | Massachusetts Institute of Technology |
last_indexed | 2024-09-23T15:02:08Z |
publishDate | 2022 |
publisher | Massachusetts Institute of Technology |
record_format | dspace |
spelling | mit-1721.1/1392272022-01-15T03:13:12Z Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry Le Thi Nguyet, Hang DiCarlo, James Chung, SueYeon Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science Although deep neural networks (DNNs) achieve excellent performance and even outperform humans on various computer vision tasks, the robustness of DNNs to small perturbations is still far from being comparable to the human visual system. Indeed, adversarial attacks, which are very small worst-case perturbations, can reduce the accuracy of state-of-the-art models dramatically to close to random chance while remaining humanly indistinguishable. Since the human visual system has a high tolerance to small input perturbations, Dapello et al developed VOneNet, a model with architecture similar to the V1 brain area as the front-end and standard DNNs architecture as the back-end, and demonstrated that VOneNet has significantly better adversarial robustness than the standard ResNet. In this work, we analyze the internal representations of adversarial examples to dissect how adversarial perturbations alter the geometric structure and encoded information of the representations and to understand how brain-like components such as representational noise and neural normalization can help to improve adversarial robustness. Firstly, we show that internal representations from adversarial examples are linearly separated and still encode a significant amount of class information. Secondly, we demonstrate that representational noise can create an overlap between noise-injected clean and adversarial examples, therefore improving the robustness of the model. Finally, we show that neural normalization, which is based on divisive normalization and lateral inhibition, achieves better adversarial performance compared to traditional normalization methods such as batch normalization, which is based on standardization. M.Eng. 2022-01-14T14:57:54Z 2022-01-14T14:57:54Z 2021-06 2021-07-12T17:39:50.610Z Thesis https://hdl.handle.net/1721.1/139227 In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/ application/pdf Massachusetts Institute of Technology |
spellingShingle | Le Thi Nguyet, Hang Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title | Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title_full | Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title_fullStr | Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title_full_unstemmed | Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title_short | Investigating the Role of Biological Constraints in Adversarial Robustness via Modeling and Representational Geometry |
title_sort | investigating the role of biological constraints in adversarial robustness via modeling and representational geometry |
url | https://hdl.handle.net/1721.1/139227 |
work_keys_str_mv | AT lethinguyethang investigatingtheroleofbiologicalconstraintsinadversarialrobustnessviamodelingandrepresentationalgeometry |