Title Information
Title
Adversarial and Real World Image Robustness of Computer Vision Models With Better Human Visual Strategy Alignment
Abstract
Deep neural networks (DNNs), which are based loosely on the ventral stream pathway of the primate visual system, are good models of the visual system because they fit neural data of the ventral steam (Yamins et al., 2013). Serre (2019) details that DNNs are also able to mimic functions of the human visual system such as image categorization, where they have achieved high accuracy. However, these models are vulnerable to adversarial attacks–small changes in image pixel values which have no effect on the accuracy of human vision. They have decreased performance when exposed to images from the ObjectNet dataset that contains objects of different rotations, viewpoints and backgrounds. The low adversarial and ObjectNet robustness of models mark a processing difference between models and the human visual system. Work by Fel et al (2022) has resulted in harmonized models, which are models that are trained on both categorization accuracy loss and a loss in alignment of human feature importance maps that capture the features in an image important for classification. Harmonized models are able to achieve high categorization accuracy as well as alignment to human visual strategies. To further explore the capabilities of harmonized models, we compare the adversarial robustness of harmonized models compared to their corresponding baseline models (models without neural harmonizer) by comparing model accuracy on the Projected Gradient Descent (LinfPGD) adversarial attack from the Foolbox toolbox. Overall, we found that although accuracy drops with increasing image perturbation, harmonized models show greater adversarial robustness compared to baseline models. Furthermore, we compare the accuracy of the models on the ObjectNet dataset and find that harmonization does not increase real world image robustness which we attribute to model limitations due to training on ImageNet.
Name: Personal
Name Part
Olaiya, Stephanie O.
Role
Role Term (marcrelator) (authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/cre")
creator
Name: Personal
Name Part
Serre, Thomas
Role
Role Term (marcrelator) (authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/ths")
thesis advisor
Name: Corporate
Name Part
Brown University. Neuroscience
Role
Role Term: Text
sponsor
Origin Information
Copyright Date
2023
Type of Resource (primo)
text_resources
Physical Description
digitalOrigin
born digital
Language
Language Term: Text (ISO639-2B) (authorityURI="http://id.loc.gov/vocabulary/iso639-2.html", valueURI="http://id.loc.gov/vocabulary/iso639-2/eng")
English
Note: thesis
Senior thesis (ScB)--Brown University, 2023
Note (displayLabel="Concentration")
Neuroscience
Genre (aat)
theses
Subject (fast) (authorityURI="http://id.worldcat.org/fast", valueURI="http://id.worldcat.org/fast/00872687")
Topic
Computer vision
Subject (fast) (authorityURI="http://id.worldcat.org/fast", valueURI="http://id.worldcat.org/fast/01167852")
Topic
Vision
Subject (fast) (authorityURI="http://id.worldcat.org/fast", valueURI="http://id.worldcat.org/fast/00872004")
Topic
Computational neuroscience
Subject (fast) (authorityURI="http://id.worldcat.org/fast", valueURI="http://id.worldcat.org/fast/")
Topic
Neuroscience
Access Condition: use and reproduction
All rights reserved
Access Condition: rights statement (href="http://rightsstatements.org/vocab/InC/1.0/")
In Copyright
Access Condition: restriction on access
All Rights Reserved