On Inherent Adversarial Robustness of Active Vision Systems
Current Deep Neural Networks are vulnerable to adversarial examples, which alter their predictions by adding carefully crafted noise. Since human eyes are robust to such inputs, it is possible that the vulnerability stems from the standard way of processing inputs in one shot by processing every pixel with the same importance. In contrast, neuroscience suggests that the human vision system can differentiate salient features by (1) switching between multiple fixation points (saccades) and (2) processing the surrounding with a non-uniform external resolution (foveation). In this work, we advocate that the integration of such active vision mechanisms into current deep learning systems can offer robustness benefits. Specifically, we empirically demonstrate the inherent robustness of two active vision methods - GFNet and FALcon - under a black box threat model. By learning and inferencing based on downsampled glimpses obtained from multiple distinct fixation points within an input, we show that these active methods achieve (2-3) times greater robustness compared to a standard passive convolutional network under state-of-the-art adversarial attacks. More importantly, we provide illustrative and interpretable visualization analysis that demonstrates how performing inference from distinct fixation points makes active vision methods less vulnerable to malicious inputs.
Code (0)
등록된 구현이 없습니다.
Tasks
Adversarial RobustnessFoveationSimilar Papers 제목 키워드 기반
A Deep Dive into Adversarial Robustness in Zero-Shot Learning
Machine learning (ML) systems have introduced significant advances in various fields, due to the introduction of highly complex models. Despite their success, it has been shown multiple times that machine learning models…
Adversarial RobustnessBIG-bench Machine LearningGeneralized Zero-Shot LearningZero-Shot LearningAttacking Bayes: On the Adversarial Robustness of Bayesian Neural Networks
Adversarial examples have been shown to cause neural networks to fail on a wide range of vision and language tasks, but recent work has claimed that Bayesian neural networks (BNNs) are inherently robust to adversarial pe…
Adversarial RobustnessPredictionSemantic Shift DetectionNavigating the Trade-off: A Synthesis of Defensive Strategies for Zero-Shot Adversarial Robustness in Vision-Language Models
This report synthesizes eight seminal papers on the zero-shot adversarial robustness of vision-language models (VLMs) like CLIP. A central challenge in this domain is the inherent trade-off between enhancing adversarial …
Zero-shot GeneralizationAdversarial RobustnessAttacks against Abstractive Text Summarization Models through Lead Bias and Influence Functions
Large Language Models have introduced novel opportunities for text comprehension and generation. Yet, they are vulnerable to adversarial perturbations and data poisoning attacks, particularly in tasks like text classific…
Abstractive Text SummarizationAdversarial RobustnessData PoisoningReading Comprehension+3On the Natural Robustness of Vision-Language Models Against Visual Perception Attacks in Autonomous Driving
Autonomous vehicles (AVs) rely on deep neural networks (DNNs) for critical tasks such as traffic sign recognition (TSR), automated lane centering (ALC), and vehicle detection (VD). However, these models are vulnerable to…
Autonomous DrivingAutonomous VehiclesTraffic Sign Recognitionvehicle detection