Towards Interpretable Deep Neural Networks by Leveraging Adversarial Examples
arXiv:1901.09035
Abstract
Sometimes it is not enough for a DNN to produce an outcome. For example, in applications such as healthcare, users need to understand the rationale of the decisions. Therefore, it is imperative to develop algorithms to learn models with good interpretability (Doshi-Velez 2017). An important factor that leads to the lack of interpretability of DNNs is the ambiguity of neurons, where a neuron may fire for various unrelated concepts. This work aims to increase the interpretability of DNNs on the whole image space by reducing the ambiguity of neurons. In this paper, we make the following contributions: 1) We propose a metric to evaluate the consistency level of neurons in a network quantitatively. 2) We find that the learned features of neurons are ambiguous by leveraging adversarial examples. 3) We propose to improve the consistency of neurons on adversarial example subset by an adversarial training algorithm with a consistent loss.
In AAAI-19 Workshop on Network Interpretability for Deep Learning
References in corpus (9)
- Explaining and Harnessing Adversarial Examples
- Caffe: Convolutional Architecture for Fast Feature Embedding
- Towards A Rigorous Science of Interpretable Machine Learning
- Striving for Simplicity: The All Convolutional Net
- Going Deeper with Convolutions
- Visualizing Deep Neural Network Decisions: Prediction Difference Analysis
- Adversarial Machine Learning at Scale
- Analyzing the Performance of Multilayer Neural Networks for Object Recognition
- Improving Interpretability of Deep Neural Networks with Semantic Information
Cited by in corpus (5)
- Explainable Text Classification in Legal Document Review A Case Study of Explainable Predictive Coding
- Interpreting Adversarial Examples with Attributes
- Explaining AlphaGo: Interpreting Contextual Effects in Neural Networks
- Investigating Robustness and Interpretability of Link Prediction via Adversarial Modifications
- Adaptive Gradient for Adversarial Perturbations Generation