Measuring the tendency of CNNs to Learn Surface Statistical Regularities
arXiv:1711.11561
Abstract
Deep CNNs are known to exhibit the following peculiarity: on the one hand they generalize extremely well to a test set, while on the other hand they are extremely sensitive to so-called adversarial perturbations. The extreme sensitivity of high performance CNNs to adversarial examples casts serious doubt that these networks are learning high level abstractions in the dataset. We are concerned with the following question: How can a deep CNN that does not learn any high level semantics of the dataset manage to generalize so well? The goal of this article is to measure the tendency of CNNs to learn surface statistical regularities of the dataset. To this end, we use Fourier filtering to construct datasets which share the exact same high level abstractions but exhibit qualitatively different surface statistical regularities. For the SVHN and CIFAR-10 datasets, we present two Fourier filtered variants: a low frequency variant and a randomly filtered variant. Each of the Fourier filtering schemes is tuned to preserve the recognizability of the objects. Our main finding is that CNNs exhibit a tendency to latch onto the Fourier image statistics of the training dataset, sometimes exhibiting up to a 28% generalization gap across the various test sets. Moreover, we observe that significantly increasing the depth of a network has a very marginal impact on closing the aforementioned generalization gap. Thus we provide quantitative evidence supporting the hypothesis that deep CNNs tend to learn surface statistical regularities in the dataset rather than higher-level abstract concepts.
Submitted
References in corpus (4)
Cited by in corpus (32)
- Neural network models and deep learning - a primer for biologists
- PanNuke Dataset Extension, Insights and Baselines
- Partial success in closing the gap between human and machine vision
- Frustratingly Simple Domain Generalization via Image Stylization
- Adversarial Examples in Modern Machine Learning: A Review
- On the Binding Problem in Artificial Neural Networks
- A neural network walks into a lab: towards using deep nets as models for human behavior
- Image classification using quantum inference on the D-Wave 2X
- Discrete and continuous representations and processing in deep learning: Looking forward
- An Explicit Local and Global Representation Disentanglement Framework with Applications in Deep Clustering and Unsupervised Object Detection
- Does enhanced shape bias improve neural network robustness to common corruptions?
- Test time Adaptation through Perturbation Robustness
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Towards Interpreting and Mitigating Shortcut Learning Behavior of NLU Models
- On the Measure of Intelligence
- Latent Adversarial Debiasing: Mitigating Collider Bias in Deep Neural Networks
- Dynamic Inference with Neural Interpreters
- PointMask: Towards Interpretable and Bias-Resilient Point Cloud Processing
- The Domain Shift Problem of Medical Image Segmentation and Vendor-Adaptation by Unet-GAN
- Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards A Fourier Perspective
- A Singular Value Perspective on Model Robustness
- Disrupting Model Training with Adversarial Shortcuts
- Predicting with High Correlation Features
- Data augmentation and image understanding
- Revisiting Edge Detection in Convolutional Neural Networks
- Metamorphic Testing of a Deep Learning based Forecaster
- Detecting Spurious Correlations with Sanity Tests for Artificial Intelligence Guided Radiology Systems
- Deep Repulsive Prototypes for Adversarial Robustness
- Can Targeted Adversarial Examples Transfer When the Source and Target Models Have No Label Space Overlap?
- Counterfactual Maximum Likelihood Estimation for Training Deep Networks
- Robust Learning with Frequency Domain Regularization
- Unsupervised Difficulty Estimation with Action Scores