Convolutional neural networks (CNNs) are the de-facto paragon for detecting the presence of objects in a scene, as portrayed by an image. CNNs are described as being “approximately invariant” to nuisance transformations such as planar translation, both by virtue of their architecture (the same operation is repeated at every location akin to a “sliding window” and is followed by local pooling) and by virtue of their approximation properties that, given sufficient parameters and transformed training data, could in principle yield discriminants that are insensitive to nuisance transformations of the data represented in the training set. In addition to planar translation, an object detector must manage variability due to scaling (possibly anisotropic along the coordinate axes, yielding different aspect ratios) and (partial) occlusion. Some nuisances are elements of a transformation group, e.g., the (anisotropic) location-scale group for the case of position, scale and aspect ratio of the object’s support.111The region of the image the objects projects onto, often approximated by a bounding box.
The fact that convolutional architectures appear effective in classifying images as containing a given object regardless of its position, scale, and aspect ratio[28, 40] suggests that the network can effectively manage such nuisance variability.
However, the quest for top performance in benchmark datasets has led researchers away from letting the CNN manage all nuisance variability. Instead, the image is first pre-processed to yield proposals, which are subsets of the image domain (bounding boxes) to be tested for the presence of a given class (Regions-with-CNN ). Proposal mechanisms aim to remove nuisance variability due to position, scale and aspect ratio, leaving a “Category CNN” to classify the resulting bounding box as one of a number of classes it is trained with. Put differently, rather than computing the posterior distribution222One can think of the conditional distribution of a class given an image , , as defined by a CNN, as the class posterior marginalized with respect to the nuisance group . If the nuisances are known, one can use the class-conditionals at each nuisance in order to approximate with a weighted average of conditionals, i.e., . When a CNN is tested on a proposal determined by a reference frame , it computes ( restricted to ), which is an approximation of . Then, explicit marginalization (assuming uniform weights) computes which is different from which in turn is different from . This approach is therefore, on average, a lower bound on proper marginalization, and the fact that it would outperform the direct computation of is worth investigating empirically. with nuisance transformations automatically marginalized, the CNN is used to compute the conditional distribution of classes given the data and a sample element that approximates the nuisance transformation, represented by a bounding box. If the goal is the nuisance itself (object support, as in detection ) it can be found via maximum-likelihood (max-out
) by selecting the bounding box that yields the highest probability of any class[19, 22]. If the goal is the class regardless of the transformation (as in categorization ), the nuisance can be approximately marginalized out
by averaging the conditional distributions with respect to an estimation of the nuisance transformations.
Now, if a CNN was an effective way of computing the marginals with respect to nuisance variability, there would be no benefit in conditioning and averaging with respect to (inferred) nuisance samples. This is a direct corollary of the Data Processing Inequality (DPI, Theorem 2.8.1 in ). Proposals are subsets of the whole image, so in theory less informative even after accounting for resolution/sampling artifacts (Fig. 1). A fortiori, performance should further decrease if the conditioning mechanism is not very representative of the nuisance distribution, as is the case for most proposal schemes that produce bounding boxes based on adaptively downsampling a coarse discretization of the location-scale group . Class posteriors conditioned on such bounding boxes discard the image outside it, further limiting the ability of the network to leverage on side information, or “context”. Should the converse be true, i.e., should averaging conditional distributions restricted to proposal regions outperform a CNN operating on the entire image, that would bring into question the ability of a CNN to marginalize nuisances such as translation and scaling or else go against the DPI. In this paper we test this hypothesis, aiming to answer to the question: How effective are current CNNs to reduce the effects of nuisance transformations of the input data, such as location and scaling?
To the best of our knowledge, this has never been done in the literature, despite the keen interest in understanding the properties of CNNs [20, 21, 34, 39, 43, 46, 47] following their empirical success. We are cognizant of the dangers of drawing sure conclusions from empirical evaluations, especially when they involve a myriad of parameters and exploit training sets that can exhibit biases. To this end, in Sect. 2 we describe a testing protocol that uses recognized existing modules, and keep all factors constant while testing each hypothesis.
We first show that a baseline (AlexNet ) with single-model top-5 error of on ImageNet 2014 Classification slightly decreases in performance (to ) when constrained to the ground-truth bounding boxes (Table 1). This may seem surprising at first, as it would appear to violate Theorem 2.6.5 of  (on average, conditioning on the true value of the nuisance transformation must reduce uncertainty in the classifier). However, note that the restriction to bounding boxes does not just condition on the location-scale group, but also on visibility, as the image outside the bounding box is ignored. Thus, the slight decrease in performance measures the loss from discarding context by ignoring the image beyond the bounding box.
When we pad the true bounding boxes with a 10-pixel rim, we show that, conditioned on such “ground-truth-with-context” indeed does decrease the error as expected, to. In Fig. 1 we show the classification performance as a function of the rim size all the way to the whole image for AlexNet and VGG16 . A rim yields the lowest top-5 errors on the ImageNet validation set for both models. This also indicates that the context effectively leveraged by current CNN architectures is limited to a relatively small neighborhood of the object of interest.
The second contribution concerns the proper sampling of the nuisance group. If we interpret the CNN restricted to a bounding box as a function that maps samples of the location-scale group to class-conditional distributions, where the proposal mechanism down-samples the group, then classical sampling theory  teaches that we should retain not the value of the function at the samples, but its local average, a process known as anti-aliasing. Also in Table 1, we show that simple uniform averaging of 4 and 8 samples of the isotropic scale group (leaving location and aspect ratio constant) reduces the error to and respectively. This is again unintuitive, as one expects that averaging conditional densities would produce less discriminative classifiers, but in line with recent developments concerning “domain-size pooling” .
|Ground-Truth Bounding Box (GT)||20.41||12.44|
|GT padded with 10 px||17.66||17.65||10.91||10.30|
|Ave-GT, 4 domain sizes (padded with [0,30] px)||15.96||16.00||9.65||8.90|
|Ave-GT, 8 domain sizes (padded with [0,70] px)||14.43||14.22||8.66||7.84|
To test the effect of such anti-aliasing on a CNN absent the knowledge of ground truth object location, we follow the methodology and evaluation protocol of  to develop a domain-size pooled CNN and test it in their benchmark classification of wide-baseline correspondence of regions selected by a generic low-level detector (MSER ). Our third contribution is to show that this procedure improves the baseline CNN by – mean AP on standard benchmark datasets (Table 3 and Fig. 5 in Sect. 2.2).
Our fourth contribution goes towards answering the question set forth in the preamble: We consider two popular baselines (AlexNet and VGG16) that perform at the state-of-the-art in the ImageNet Classification challenge and introduce novel sampling and pruning methods, as well as an adaptively weighted marginalization based on the inverse Rényi entropy. Now, if averaging the conditional class posteriors obtained with various sampling schemes should improve overall performance, that would imply that the implicit “marginalization” performed by the CNN is inferior to that obtained by sampling the group, and averaging the resulting class conditionals. This is indeed our observation, e.g., for VGG16, as we achieve an overall performance of , compared to when using the whole image (Table 2). There are, however, caveats to this answer, which we discuss in Sect. 3.
Our fifth contribution is to actually provide a method that performs at the state of the art in the ImageNet Classification challenge when using a single model. In Table 2 we provide various results and time complexity. We achieve a top-5 classification error of and for AlexNet and VGG16, compared to and error when they are tested with regularly sampled crops , which corresponds to and relative error reduction, respectively. Data augmentation techniques such as scale jittering and an ensemble of several models [23, 40, 42] could be deployed along with our method.
The source code implementing our method and the scripts necessary to reproduce the evaluation are available at http://vision.ucla.edu/~nick/proj/cnn_nuisances/.
1.2 Related work
The literature on CNNs and their role in Computer Vision is rapidly evolving. Attempts to understand the inner workings of CNNs are being conducted[6, 20, 21, 29, 34, 39, 43, 46, 47], along with theoretical analysis [2, 4, 8, 41] aimed at characterizing their representational properties. Such intense interest was sparked by the surprising performance of CNNs [6, 11, 19, 23, 28, 36, 37, 40, 42] in Computer Vision benchmarks [10, 15], where many couple a proposal scheme [1, 5, 7, 14, 24, 25, 27, 31, 35, 44, 48] with a CNN. As our work relates to a vast body of work, we refer the reader to references in the papers that describe the benchmarks we adopt, namely ,  and .
Bilen et. al.  also explore the idea of introducing proposals in classification. However, their approach leverages on a significantly larger number of candidates and focuses on sophisticated classifiers and post-normalization of class posteriors. Our investigation targets selecting a very small subset of the most discriminative candidates among generic object proposals, while building on popular CNN models.
2.1 Large-scale Image Classification
What if we trivialize location and scaling?
First, we test the hypothesis that eliminating the nuisances of location and scaling by providing a bounding box for the object of interest will improve the classification accuracy. This is not a given, for restricting the network to operate on a bounding box prevents it from leveraging on context outside it. We use the AlexNet and VGG16 pretrained models, which are provided with the MatConvNet open source library , and test their top-1 and top-5 classification errors on the ImageNet 2014 classification challenge . The validation set consists of images, where at each of them one “salient” class is annotated a priori by a human. However, other ImageNet classes appear in many of the images, which can confound any classifier.
We test the classifier in various settings (Table 1); first, by feeding the entire image to it and letting the classifier manage the nuisances. Then we test the ground-truth annotated bounding box and concentric regions that include it. We try both isotropic and anisotropic expansion of the ground-truth region. We observe similar behavior, which is also consistent for both models.
Only for AlexNet at Table 1 using the object’s ground-truth support performs slightly worse than using the whole image. After we pad the object region with a -pixel rim, the top-5 classification error decreases fast. However, there is a trade-off between context and clutter. Providing too much context has diminishing returns. In Fig. 1 we show how the errors vary as a function of the rim size around the object of interest. Performance starts dropping down when we add more than rim size. This padding gives and top-5 error for AlexNet and VGG16, as opposed to and respectively, when classifying the whole image.
To ensure that this improvement is not due to downsampling, we repeat the experiment with fixed resolution for the whole image and every subregion. We achieve this by shrinking each region with the same downsampling factor that we apply to the whole image to pass to the CNN. Finally we rescale the downsampled region to the CNN input. These results appear with the label “same resolution” in Fig. 1.
Finally, we apply domain size average pooling on the class posterior (i.e., the network’s softmax output layer) with and domain sizes that are concentric with the ground truth. The added rim has the declared size either at both dimensions (for the anisotropic case) or only along the minimum dimension (for the isotropic case), and it is uniformly sampled in the range and , respectively. The latter one further reduces the top-5 error to for AlexNet, which is lower than any single domain size (c.f. Fig. 1). This suggests that explicitly marginalizing samples can be beneficial. Next we test whether the improvement stands when using object proposals.
Introducing object proposals.
First, we decide the number of proposals which will provide a satisfactory cover for the majority of objects present in the dataset. In a single image we search for the highest Intersection over Union (IoU) overlap between the ground-truth region and any proposed sample and in turn we evaluate the network’s performance on the most overlapping sample. We repeat this process for various number of proposals in a small subset of validation set and finally choose , which provides a satisfactory trade-off between classification performance and computational cost.
Among the extracted proposals, we choose the most informative subset for our task, based on pruning criteria that we introduce later. Next we discuss what other samples we use, which are also drawn in Fig. 2.
Domain-size pooling and regular crops.
We investigate the influence of domain-size pooling at test time both as stand-alone technique and as additional proposals for the final method which is described in Algorithm 1. We deploy domain-size aggregation of the network’s class posterior over sizes that are uniformly sampled in the range , where is the normalized size of the original image. After parameter search, we choose and . We use both the original and the horizontally flipped area, which gives samples in total.
Continuing to sample patches within the image has diminishing return in terms of discriminability, while including more background patches with noisy class posterior distribution. We adopt an information-theoretic criterion to filter the samples that we use for the subsequent approximate marginalization.
For each proposal we evaluate the network and take the normalized softmax output , where and
on ILSVRC classification. The output is a set of non-negative numbers which sum up to 1. We can interpret the vector
as a probability distribution on the discrete space of classesand compute the Rényi entropy as .
Our conjecture is that more discriminative class distributions tend to be more peaky with less ambiguity among the classes, and therefore lower entropy. In Fig. 3 we show how selecting a subset of image patches whose class posterior has lower entropy improves classification performance.
We extract candidate object proposals333We introduce a prior encouraging the largest proposals among the ones that the standard setting in  would give. To this end, instead of directly extracting, for example, proposals, we generate and keep the largest ones (Algorithm 1).  and evaluate the network for both the original candidates and their horizontal flips. Then we keep a small subset , whose posterior distribution has the lowest entropy. We use Rényi entropy with relatively small powers (), as we found that it encourages selecting regions with more than one highly-confident candidate object. While the parameter increases, the entropy is increasingly determined by the events of highest probability. Larger would be more effective for images with a single object, which is not the case in most images in ILSVRC.
Finally we introduce a weighted average of the selected posteriors as , where is the support of sample and is the weight of its posterior. We try both uniform weights and weights proportional to the inverse entropy of the posterior . The latter is expected to perform better, as it naturally gives higher weight to the most discriminative samples.
|crops||sizes||proposals||top-1||top-5||t (s/im)||top-1||top-5||t (s/im)|
To compare various sampling and inference strategies, we use the AlexNet and VGG16 models. All classification results in Table 2 refer to the validation set of the ILSVRC 2014 , except for the last row which demonstrates results on the test set. On the rows – we show the performance of popular multi-crop methods [28, 40, 42]. Then we compare them with strategies that involve concentric domain sizes (rows –) and object proposals (rows –).
Before extracting the crops and in order to preserve the aspect ratio of each single image, we rescale it so that its minimum dimension is . The proposals are extracted at the original image resolution and then they are rescaled anisotropically to fit the model’s receptive field. Additionally, some multi-crop algorithms resize the image in different scales and then sample patches of fixed size densely over the image. Szegedy et al.  use scales and crops per scale, which yields patches in all. Following the methodology from Simonyan et al. , it is comparable to deploy scales and extract crops per scale ( regular grid with flips), for a total of crops over scales (row in Table 2).
The results, presented in Table 2, indicate as expected that scale jittering at test time improves the classification performance for both 10-crop and 50-crop strategies. Additionally, the 50-crop strategy is better than the 10-crop strategy for both models. The results on row 5 in bold are the lowest errors that can be achieved with these specific single models444Specifically, we use the VGG16 model which is trained without scale jittering at training and appears on the first row of D area in Table 3 in . Pre-trained models for both AlexNet and VGG16 are publicly available with the MatConvNet toolbox . Simonyan et al. in their evaluation with crops and scales report top-5 error on ImageNet 2014 validation. In contrast our implementation produces and there might also be minor differences in the training process. using only regular crops.
Then we present our methods and observe that using the AlexNet network with concentric domain sizes outperforms most multi-crop algorithms even if it only evaluates and averages patches. Furthermore, combining it with common crops achieves the best results for both networks, even without using -scale jittering. One interpretation for these improvements is that the concentric samples serve a natural prior for the majority of ILSVRC images, i.e., the object of interest lies most probably at the center than at the image boundaries. This is a common assumption in the literature that also appears in large-scale video segmentation .
Following, we introduce the adaptive sampling mechanism with Algorithm 1 and reduce the top-5 error to and for AlexNet and VGG16 respectively. To set this in perspective, Krizhevsky et al.  report top-5 error when they combine 5 models. We improve this performance with one single model. The relative improvement for the deployed instances of AlexNet and VGG16, compared to the data-augmentation methods used in [40, 42], is and , respectively. Row shows results where the marginalization is weighted based on the entropy (notated as ), while the methods in rows – use uniform weights (c.f. Algorithm 1). At the last row we show results from the ILSVRC test server for our top-performing method (row ).
Regular and concentric crops assume that objects occupy most of the image or appear near the center. This is a known bias in the ImageNet dataset. To analyze the effect of adaptive sampling, we calculate the intersection over union error between the objects and the regular and concentric crops, and show in Fig. 4 the performance of various methods as a function of the IoU error. The improvement of using adaptive sampling (via proposals) over only regular and concentric crops is increased as IoU error grows, indicating that objects occupy less domain or are far away from the center.
In Table 2 we show the number of evaluated samples () and the subset that is actually averaged () to extract a single class posterior vector. The sequential time needed for each method is linear to the number of evaluated patches . We run the experiments with the MatConvNet library and parallelize the load for VGG16 so that the testing is done in batches of patches. We report the time profile555We use a machine equipped with a NVIDIA Tesla K80 GPU, 24 Intel Xeon E5 cores and 64G RAM memory. for each method in Table 2. A few entries cover two boxes, as their methods are evaluated together. Extracting the proposals is not a major bottleneck if using an efficient algorithm , such as Edge Boxes . In rows –
we report results of our faster version, where the Edge Boxes do not leverage edge sharpening and use one decision tree. Overall, compared to the-crop strategy, the object proposal scheme introduces marginal computational overhead.
2.2 Wide-Baseline Correspondence
We test the effect of domain-size pooling in correspondence tasks with a convolutional architecture, as done by  for SIFT , using the datasets and protocols of . This is illustrated in Fig. 2 (upper right), but here the domain sizes are centered around the detector. We expect that such averaging will increase the discriminability of detected regions and in turn the matching ability, similar to the benefits that we see on the last rows of Table 1.
We use maximally-stable extremal regions (MSER)  to detect candidate regions, affine-normalize them, align them to the dominant orientation, and re-scale them for head-to-head comparisons. For a detected scale at each MSER, the DSP-CNN samples domain sizes within a neighborhood around it, computes the CNN responses on these samples and averages the posteriors. The deployed deep network is the unsupervised convolutional network proposed by , which is trained with surrogate labels from an unlabeled dataset (see the methodology in ), with the objective of being invariant to several transformations that are commonly observed in images captured from different viewpoints. As opposed to network-classifiers, here the task is correspondence and the network is purely a region descriptor, whose last two layers ( and ) are the representations.
|DSP-CNN-L34 (concat. PCA128)||256||52.69|
In Fig. 5 (left) we show the comparison between CNN and DSP-CNN on Oxford dataset . CNN’s layer 4 is the representation for each MSER and DSP-CNN simply averages this layer’s responses for all domain sizes. We use , and sizes that are uniformly sampled in this neighborhood. There is a improvement based on the matching mean average precision.
Fischer’s dataset  includes pairs of images, some of them with more extreme transformations than those in the Oxford dataset. The types of transformations include zooming, blurring, lighting change, rotation, perspective and nonlinear transformations. In Fig. 5 (center) and Table 3 we show comparisons between CNN and DSP-CNN for layer-3 and layer-4 representations and demonstrate and relative improvement. We use , and domain sizes. These parameters are selected with cross-validation. In Table 3 we show comparisons with baselines, such as using the raw data and DSP-SIFT . After fine parameter search (, ) and concatenating the layers and , we achieve state of the art performance as shown in Fig. 5 (right), observing though the high dimensionality of this method compared to local descriptors.
Given the inherent high-dimensionality of CNN layers, we perform dimensionality reduction with principal component analysis to investigate how this affects the matching performance. In Table3 we show the performance for compressed layer-3 and layer-4 representations with PCA to dimensions and their concatenation. There is a modest performance loss, yet the compressed features outperform the single-scale features by a large margin.
Our empirical analysis indicates that CNNs, that are designed to be invariant to nuisance variability due to small planar translations – by virtue of their convolutional architecture and local spatial pooling – and learned to manage global translation, distance (scale) and shape (aspect ratio) variability by means of large annotated datasets, in practice are less effective than a naive and in theory counter-productive practice of sampling and averaging the conditionals based on an ad-hoc choice of bounding boxes and their corresponding planar translation, scale and aspect ratio.
This has to be taken with the due caveats: First, we have shown the statement empirically for few choices of network architectures (AlexNet and VGG), trained on particular datasets that are unlikely to be representative of the complexity of visual scenes (although they may be representative of the same scenes as portrayed in the test set), and with a specific choice of parameters made by their respective authors, both for the classifier and for the evaluation protocol. To test the hypothesis in the fairest possible setting, we have kept all these choices constant while comparing a CNN trained, in theory, to “marginalize” the nuisances thus described, with the same applied to bounding boxes provided by a proposal mechanism. To address the arbitrary choice of proposals, we have employed those used in the current state-of-the-art methods, but we have found the results representative of other choices of proposals.
In addition to answering the question posed in the introduction, along the way we have shown that by framing the marginalization of nuisance variables as the averaging of a sub-sampling of marginal distributions we can leverage of concepts from classical sampling theory to anti-alias the overall classifier, which leads to a performance improvement both in categorization, as measured in the ImageNet benchmark, and correspondence, as measured in the Oxford and Fischer’s matching benchmarks.
Of course, like any universal approximator, a CNN can in principle capture the geometry of the discriminant surface by “learning away” nuisance variability, given sufficient resources in terms of layers, number of filters, and number of training samples. So in the abstract sense a CNN can indeed marginalize out nuisance variability. The analysis conducted show that, at the level of complexity imposed by current architectures and training set, it does so less effectively than ad-hoc averaging of proposal distributions.
This leaves researchers the choice of investing more effort in the design of proposal mechanisms [18, 36], subtracting duties from the Category CNN downstream, or invest more effort in scaling up the size and efficiency of learning algorithms for general CNNs so as to render the need for a proposal scheme moot.
This research is supported by ARO W911NF-15-1-0564/66731-CS, ONR N00014-13-1-034, and AFOSR FA9550-15-1-0229. We gratefully acknowledge NVIDIA Corporation for donating a K40 GPU that was used in support of some of the experiments.
-  B. Alexe, T. Deselaers, and V. Ferrari. Measuring the objectness of image windows. In IEEE Transactions on Pattern Analysis and Machine Intelligence, 2012.
-  F. Anselmi, L. Rosasco, and T. Poggio. On Invariance and Selectivity in Representation Learning. arXiv preprint arXiv:1503.05938, 2015.
-  H. Bilen, M. Pedersoli and T. Tuytelaars. Weakly supervised object detection with posterior regularization. In British Machine Vision Conference, 2014.
-  J. Bruna and S. Mallat. Invariant scattering convolution networks. In IEEE Transactions on Pattern Analysis and Machine Intelligence, 2013.
-  J. Carreira and C. Sminchisescu. CPMC: Automatic object segmentation using constrained parametric min-cuts. In IEEE Transactions on Pattern Analysis and Machine Intelligence, 2012.
-  K. Chatfield, K. Simonyan, A. Vedaldi, and A. Zisserman. Return of the devil in the details: Delving deep into convolutional nets. In British Machine Vision Conference, 2014.
M. Cheng, Z. Zhang, W. Lin, and P. Torr.
BING: Binarized normed gradients for objectness estimation at 300fps.In
IEEE Conference on Computer Vision and Pattern Recognition, 2014.
T. Cohen and M. Welling.
Learning the irreducible representations of commutative lie groups.
International Conference on Machine Learning, 2014.
-  T. M. Cover and J. A. Thomas. Elements of Information Theory. John Wiley & Sons, 2012.
-  J. Deng, W. Dong, R. Socher, L. J. Li, K. Li, and F.-F. Li. ImageNet: A large-scale hierarchical image database. In IEEE Conference on Computer Vision and Pattern Recognition, 2009.
-  J. Donahue, L. A. Hendricks, S. Guadarrama, M. Rohrbach, S. Venugopalan, K. Saenko, and T. Darrell. Long-term recurrent convolutional networks for visual recognition and description. In IEEE Conference on Computer Vision and Pattern Recognition, 2015.
-  J. Dong and S. Soatto. Domain-size pooling in local descriptors: DSP-SIFT. In IEEE Conference on Computer Vision and Pattern Recognition, 2015.
-  A. Dosovitskiy, J. Springenberg, M. Riedmiller and T. Brox. Unsupervised feature learning by augmenting single images. In Advances in Neural Information Processing Systems, 2014.
-  D. Erhan, C. Szegedy, A. Toshev, and D. Anguelov. Scalable object detection using deep neural networks. In IEEE Conference on Computer Vision and Pattern Recognition, 2014.
-  M. Everingham, L. V. Gool, C. Williams, J. Winn, and A. Zisserman. The Pascal Visual Object Classes (VOC) challenge. In International Journal of Computer Vision, 2010.
-  P. Fischer, A. Dosovitskiy, and T. Brox. Descriptor matching with convolutional neural networks: a comparison to sift. arXiv preprint arXiv:1405.5769, 2014.
-  R. Gens, and P. Domingos. Deep Symmetry Networks. In Advances in Neural Information Processing Systems, 2014.
-  R. Girshick. Fast R-CNN. In IEEE International Conference on Computer Vision, 2015.
-  R. Girshick, J. Donahue, T. Darrell, and J. Malik. Rich feature hierarchies for accurate object detection and semantic segmentation. In IEEE Conference on Computer Vision and Pattern Recognition, 2014.
-  I. Goodfellow, H. Lee, Q. V. Le, A. Saxe, and A. Y. Ng. Measuring invariances in deep networks. In Advances in Neural Information Processing Systems, 2009.
-  I. Goodfellow, J. Shlens, and C. Szegedy. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations, 2015.
-  K. He, X. Zhang, S. Ren, and J. Sun. Spatial pyramid pooling in deep convolutional networks for visual recognition. In IEEE European Conference on Computer Vision, 2014.
-  K. He, X. Zhang, S. Ren, and J. Sun. Delving deep into rectifiers: Surpassing human-level performance on ImageNet classification. In IEEE International Conference on Computer Vision, 2015.
-  J. Hosang, R. Benenson, P. Dollár, and B. Schiele. What makes for effective detection proposals? In IEEE Transactions on Pattern Analysis and Machine Intelligence, 2015.
-  A. Humayun, F. Li, and J. M. Rehg. RIGOR: Reusing inference in graph cuts for generating object regions. In IEEE Conference on Computer Vision and Pattern Recognition, 2014.
-  A. Karpathy, G. Toderici, S. Shetty, T. Leung, R. Sukthankar and L. Fei-Fei. Large-scale video classification with convolutional neural networks. In IEEE Conference on Computer Vision and Pattern Recognition, 2014.
-  P. Krähenbühl and V. Koltun. Geodesic object proposals. In IEEE European Conference on Computer Vision, 2014.
-  A. Krizhevsky, I. Sutskever, and G. E. Hinton. ImageNet classification with deep convolutional neural networks. In Advances in Neural Information Processing Systems, 2012.
C.-Y. Lee, S. Xie, P. Gallagher, Z. Zhang, and Z. Tu.
International Conference on Artificial Intelligence and Statistics, 2015.
-  D. G. Lowe. Distinctive image features from scale-invariant keypoints. In International Journal of Computer Vision, 2004.
-  S. Manen, M. Guillaumin, and L. V. Gool. Prime object proposals with randomized Prim’s algorithm. In IEEE International Conference on Computer Vision, 2013.
-  J. Matas, O. Chum, M. Urban, and T. Pajdla. Robust wide-baseline stereo from maximally stable extremal regions. In Image and Vision Computing, 2004.
-  K. Mikolajczyk, T. Tuytelaars, C. Schmid, A. Zisserman, J. Matas, F. Schaffalitzky, T. Kadir, and L. Van Gool. A comparison of affine region detectors. In International Journal of Computer Vision, 2005.
-  A. Nguyen, J. Yosinski, and J. Clune. Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In IEEE Conference on Computer Vision and Pattern Recognition, 2015.
-  E. Rahtu, J. Kannala, and M. Blaschko. Learning a category independent object detection cascade. In IEEE International Conference on Computer Vision, 2011.
-  S. Ren, K. He, R. Girshick, and J. Sun. Faster R-CNN: Towards real-time object detection with region proposal networks. In Advances in Neural Information Processing Systems, 2015.
-  P. Sermanet, D. Eigen, X. Zhang, M. Mathieu, R. Fergus, and Y. LeCun. Overfeat: Integrated recognition, localization and detection using convolutional networks. In International Conference on Learning Representations, 2014.
-  C. E. Shannon. A mathematical theory of communication. In ACM SIGMOBILE Mobile Computing and Communications Review, 2001.
-  K. Simonyan, A. Vedaldi, and A. Zisserman. Deep inside convolutional networks: Visualising image classification models and saliency maps. In International Conference on Learning Representations, 2014.
-  K. Simonyan and A. Zisserman. Very deep convolutional networks for large-scale image recognition. In International Conference on Learning Representations, 2015.
-  S. Soatto and A. Chiuso. Visual Representations: Defining properties and deep approximation. In International Conference on Learning Representations, 2016.
-  C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich. Going deeper with convolutions. In IEEE Conference on Computer Vision and Pattern Recognition, 2015.
-  C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus. Intriguing properties of neural networks. In International Conference on Learning Representations, 2014.
-  J. Uijlings, K. van de Sande, T. Gevers, and A. Smeulders. Selective search for object recognition. International Journal of Computer Vision, 2013.
-  A. Vedaldi and K. Lenc. MatConvNet: Convolutional neural networks for MATLAB. In ACM Conference on Multimedia Conference, 2015.
-  J. Yosinski, J. Clune, Y. Bengio, and H. Lipson. How transferable are features in deep neural networks? In Advances in Neural Information Processing Systems, 2014.
-  M. D. Zeiler and R. Fergus. Visualizing and understanding convolutional networks. In IEEE European Conference on Computer Vision, 2014.
-  C. L. Zitnick and P. Dollár. Edge boxes: Locating object proposals from edges. In IEEE European Conference on Computer Vision, 2014.