The range of harmful frequency for DNN corruption robustness

The range of harmful frequency for DNN corruption robustness
复制标题

DOI:
10.1016/j.neucom.2022.01.087
复制
发表时间:
2022-01
期刊:
影响因子:
6
通讯作者:
Zhuang Zhang;Dejian Meng;Lijun Zhang;Wei Xiao;W. Tian
Zhuang Zhang;Dejian Meng;Lijun Zhang;Wei Xiao;W. Tian
中科院分区:
计算机科学2区
文献类型:
--
作者:
Zhuang Zhang;Dejian Meng;Lijun Zhang;Wei Xiao;W. Tian

文献摘要

相似文献

尽管深度神经网络在各种任务上都取得了优异的性能,但已被证明容易受到图像损坏(噪声,模糊等)的影响。了解这个漏洞是实现强大DNN的关键一步。因此,许多研究人员分析了图像的频域,并将这种脆弱性归因于高频。然而,他们只是定性地描述了“高频率”的相对规模没有量化的范围有害的高频率。为了填补这一空白,更深入地了解腐败的鲁棒性,我们分析了8 SOTA模型的图像频率分量的重要性和腐败的鲁棒性之间的相关性。结果表明,约6/7的高频图像是有害的。基于我们的见解,我们提出了一种图像增强方法,该方法通过对训练图像的有害频率进行洗牌来降低有害频率对DNN的重要性。在ResNet 50上的实验表明,与SOTA方法相比,我们的方法以最少的时间消耗实现了相当的DNN腐败鲁棒性。更重要的是,我们的图像增强在DNN(例如ResNet 18,VGG 16)和腐败基准(例如Cifar-10-C,MNIST-C)中表现出良好的泛化能力。我们的研究从定量的角度加深了我们对模型鲁棒性和高频之间关系的理解,并表明通过准确识别有害频率,我们可以有效地提高DNN腐败鲁棒性,而无需像其他SOTA方法那样使用额外的模型辅助或多个变换组合。
Despite having achieved excellent performance on various tasks, deep neural networks have been shown to be vulnerable to image corruptions (noise, blur, etc.). Understanding this vulnerability is a critical step towards robust DNN. Therefore, many researchers analyzed the frequency domain of images and attributed this vulnerability to the high frequency. However, they only qualitatively describe ‘high frequency’ on a relative scale without quantifying the range of harmful high frequency. To fill this gap and obtain a deeper insight into the corruption robustness, we analyze the correlation between the importance of image frequency components for 8 SOTA models and the corruption robustness of them. Results show that about 6/7 high frequency of the images is harmful. Based on our insight, we propose an image augmentation method, which reduces the importance of harmful frequency to DNN by shuffling the harmful frequency of training images. Experiments on ResNet50 show that, compared with SOTA methods, our method achieves comparable DNN corruption robustness with the least time consumption. What’s more, our image augmentation shows a good generalization across DNNs (e.g. ResNet18, VGG16) and corruption benchmarks (e.g. Cifar-10-C, MNIST-C). Our study has enhanced our understanding of the relationship between model robustness and high frequency from a quantitative perspective and shows that by accurately identifying harmful frequency, we can effectively improve DNN corruption robustness without using additional model assistance or multiple transformation combinations like other SOTA methods.