The range of harmful frequency for DNN corruption robustness
The range of harmful frequency for DNN corruption robustness
复制标题
DOI:
10.1016/j.neucom.2022.01.087
复制
发表时间:
2022-01
期刊:
影响因子:
6
通讯作者:
Zhuang Zhang;Dejian Meng;Lijun Zhang;Wei Xiao;W. Tian
中科院分区:
文献类型:
--
作者:
Zhuang Zhang;Dejian Meng;Lijun Zhang;Wei Xiao;W. Tian
Despite having achieved excellent performance on various tasks, deep neural networks have been shown to be vulnerable to image corruptions (noise, blur, etc.). Understanding this vulnerability is a critical step towards robust DNN. Therefore, many researchers analyzed the frequency domain of images and attributed this vulnerability to the high frequency. However, they only qualitatively describe ‘high frequency’ on a relative scale without quantifying the range of harmful high frequency. To fill this gap and obtain a deeper insight into the corruption robustness, we analyze the correlation between the importance of image frequency components for 8 SOTA models and the corruption robustness of them. Results show that about 6/7 high frequency of the images is harmful. Based on our insight, we propose an image augmentation method, which reduces the importance of harmful frequency to DNN by shuffling the harmful frequency of training images. Experiments on ResNet50 show that, compared with SOTA methods, our method achieves comparable DNN corruption robustness with the least time consumption. What’s more, our image augmentation shows a good generalization across DNNs (e.g. ResNet18, VGG16) and corruption benchmarks (e.g. Cifar-10-C, MNIST-C). Our study has enhanced our understanding of the relationship between model robustness and high frequency from a quantitative perspective and shows that by accurately identifying harmful frequency, we can effectively improve DNN corruption robustness without using additional model assistance or multiple transformation combinations like other SOTA methods.