用对抗鲁棒性提升CLIP模型在脑解码中的表现
Rethinking Brain Decoding with CLIP: The Role of Adversarial Robustness

- 用对抗训练改进CLIP的视觉表征,使其更符合大脑活动模式
- 在NSD和GOD数据集上,任务性能显著提升,对齐度更高
- 适合关注脑机接口与神经表征建模的研究者
脑解码旨在通过脑信号推断刺激相关的表征。在fMRI研究中,通常将fMRI响应映射到计算模型的潜在表征。近年来,由于其丰富的视觉-语言嵌入空间,CLIP成为脑解码的热门选择。然而,将fMRI信号与CLIP表征对齐仍具挑战性,因CLIP未专门优化神经对齐,其表征可能包含仅部分反映在脑活动中的统计预测线索,限制解码性能。本文探究对抗鲁棒表征是否能改善以CLIP为基础的脑解码。对抗训练抑制非鲁棒特征,促进更稳定、感知结构化的表征,可能更契合脑活动。我们在fMRI图像检索和零样本分类任务上,固定解码器,仅改变目标表征(标准CLIP vs. 鲁棒变体),在NSD和GOD数据集上进行评估。实验结果表明,这一简单调整持续提升任务性能,并在多个指标上实现更强对齐。归因分析显示,标准CLIP与其鲁棒变体之间一致性低,表明对抗鲁棒性重构了视觉表征的特征重要性。这些发现表明,目标表征的选择影响脑解码性能,对抗鲁棒性可作为脑解码的重要筛选标准。
原文摘要 · Abstract (English)
Brain decoding aims to uncover neural mechanisms by inferring stimulus-related representations from brain signals. In fMRI studies, this is typically achieved by mapping fMRI responses to the latent representations of computational models. Recently, CLIP has become a popular choice for brain decoding due to its rich vision--language embedding space. However, aligning fMRI signals with CLIP representations remains challenging. As CLIP is not explicitly optimized for neural alignment, its representations may capture statistically predictive cues that are only partially reflected in brain activity, limiting decoding performance. In this paper, we investigate whether adversarially robust representations improve neural decoding with CLIP. Adversarial training suppresses non-robust features and promotes more stable, perceptually structured representations, which may better align with brain activity. We evaluate this by fixing the fMRI decoder and varying only the target representation (standard CLIP vs. robust variants) on fMRI-image retrieval and zero-shot classification tasks across NSD and GOD datasets. Empirical results show that this simple change consistently improves task performance and yields stronger alignment across multiple metrics. Attribution analysis further reveals consistently low agreement between standard CLIP and its robust variants, suggesting that adversarial robustness reorganizes feature importance in the visual representation. These findings suggest that the choice of target representation influences neural decoding performance and that adversarial robustness may serve as a useful criterion for brain decoding.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。