用人类脑电数据训练模型,小幅提升对抗鲁棒性。
Limited but consistent gains in adversarial robustness by co-training object recognition models with human EEG
- 用图像分类+脑电预测双任务训练ResNet50,对齐人脑响应。
- 脑电预测越准,对抗攻击下的准确率提升越明显(100ms峰值)。
- 效果虽小但稳定,尤其来自顶枕区电极的信号贡献大。
与人类视觉不同,人工神经网络仍易受对抗攻击影响。为缓解此问题,研究尝试将人脑的归纳偏置转移至神经网络,通常通过让网络表征匹配生物脑响应实现。以往工作依赖鼠类或灵长类动物的侵入式脑数据,采自特定脑区,在非自然条件下(如麻醉状态)并使用缺乏多样性和自然性的刺激数据集。本研究探索将模型表征对齐人类在真实世界图像上的脑电响应,能否提升网络鲁棒性。具体地,我们训练了基于ResNet50的模型完成分类与脑电预测双重任务,并评估其脑电预测准确率及对抗攻击下的表现。结果显示,网络在刺激后约100毫秒时的脑电预测准确率与对抗鲁棒性提升显著相关。尽管效应量有限,但结果在不同随机初始化和模型架构下保持一致。进一步分析单个脑电通道发现,顶枕区电极贡献最显著。该结果表明人类脑电可用于此类任务,为未来在更大数据集、多样化刺激下实现更强效果开辟路径。
原文摘要 · Abstract (English)
In contrast to human vision, artificial neural networks (ANNs) remain relatively susceptible to adversarial attacks. To address this vulnerability, efforts have been made to transfer inductive bias from human brains to ANNs, often by training the ANN representations to match their biological counterparts. Previous works relied on brain data acquired in rodents or primates using invasive techniques, from specific regions of the brain, under non-natural conditions (anesthetized animals), and with stimulus datasets lacking diversity and naturalness. In this work, we explored whether aligning model representations to human EEG responses to a rich set of real-world images increases robustness to ANNs. Specifically, we trained ResNet50-backbone models on a dual task of classification and EEG prediction; and evaluated their EEG prediction accuracy and robustness to adversarial attacks. We observed significant correlation between the networks' EEG prediction accuracy, often highest around 100 ms post stimulus onset, and their gains in adversarial robustness. Although effect size was limited, effects were consistent across different random initializations and robust for architectural variants. We further teased apart the data from individual EEG channels and observed strongest contribution from electrodes in the parieto-occipital regions. The demonstrated utility of human EEG for such tasks opens up avenues for future efforts that scale to larger datasets under diverse stimuli conditions with the promise of stronger effects.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。