Towards Frequency-Based Explanation for Robust CNN

05/06/2020
by   Zifan Wang, et al.
0

Current explanation techniques towards a transparent Convolutional Neural Network (CNN) mainly focuses on building connections between the human-understandable input features with models' prediction, overlooking an alternative representation of the input, the frequency components decomposition. In this work, we present an analysis of the connection between the distribution of frequency components in the input dataset and the reasoning process the model learns from the data. We further provide quantification analysis about the contribution of different frequency components toward the model's prediction. We show that the vulnerability of the model against tiny distortions is a result of the model is relying on the high-frequency features, the target features of the adversarial (black and white-box) attackers, to make the prediction. We further show that if the model develops stronger association between the low-frequency component with true labels, the model is more robust, which is the explanation of why adversarially trained models are more robust against tiny distortions.

READ FULL TEXT
research
05/28/2019

High Frequency Component Helps Explain the Generalization of Convolutional Neural Networks

We investigate the relationship between the frequency spectrum of image ...
research
04/03/2022

Improving Vision Transformers by Revisiting High-frequency Components

The transformer models have shown promising effectiveness in dealing wit...
research
12/09/2021

Model Doctor: A Simple Gradient Aggregation Strategy for Diagnosing and Treating CNN Classifiers

Recently, Convolutional Neural Network (CNN) has achieved excellent perf...
research
08/19/2021

Amplitude-Phase Recombination: Rethinking Robustness of Convolutional Neural Networks in Frequency Domain

Recently, the generalization behavior of Convolutional Neural Networks (...
research
07/19/2023

Towards Building More Robust Models with Frequency Bias

The vulnerability of deep neural networks to adversarial samples has bee...
research
01/12/2023

Phase-shifted Adversarial Training

Adversarial training has been considered an imperative component for saf...
research
06/04/2021

Can convolutional ResNets approximately preserve input distances? A frequency analysis perspective

ResNets constrained to be bi-Lipschitz, that is, approximately distance ...

Please sign up or login with your details

Forgot password? Click here to reset