Keynotes | K&Ts | GACs | Talks | Posters | Search

Poster F in Poster Session F: Thursday, August 6, 1:45 – 3:30 pm, Kimmel Center, Shorin & Rosenthal Rooms

Dissociating spatial frequency reliance from adversarial robustness advantages in neurally guided deep convolutional neural networks

Zhenan Shao1, Tianyu Ren2, Chengxiao Wang2, Leyla Isik1, Diane Beck2; 1Johns Hopkins University, 2University of Illinois at Urbana-Champaign

Presenter: Zhenan Shao

Deep convolutional neural networks (DCNNs) have approached and even surpassed human-level performance on many visual tasks, yet they remain strikingly vulnerable to near-imperceptible perturbations generated by adversarial attacks. Recent studies demonstrate that aligning DCNN representations with human visual cortex activity improves adversarial robustness, but the mechanisms driving such advantage remain yet to be understood. One line of research suggests that neural alignment confers robustness by biasing models towards the low spatial frequencies (LSF). However, recent work indicates that human object recognition critically depends on a narrow, mid-frequency "human channel" which was partially preserved in prior LSF-focused studies. Here, we aim to explicitly test whether a spectral bias towards the LSF or the human channel is the primary driver of adversarial robustness observed in neurally aligned DCNNs. We first demonstrate that DCNNs aligned to higher-order regions of the human ventral visual stream systematically increase their reliance on both the LSF and the human channel. However, explicitly steering DCNNs towards either channel fails to confer adversarial robustness. These results suggest that both LSF and human-channel biases are emergent correlates of learning human-like representations rather than the driving mechanism conferring adversarial robustness.

Topic Area: Computational Models of Vision & Visual Cortex