আর্জেন্টিনা বনাম

আর্জেন্টিনা জাতীয় ফুটবল দল

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarially Robust Neural Style Transfer

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarially Robust Neural Style Transfer


A figure in Ilyas, et. al. that struck me as particularly
interesting
was the following graph showing a correlation between adversarial transferability between architectures and
their
tendency to learn similar non-robust features.

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarially Robust Neural Style Transfer
Adversarial transferability vs test accuracy of different architectures trained on ResNet-50′s
non-robust features.

One way to interpret this graph is that it shows how well a particular architecture is able to capture
non-robust features in an image.
Since the non-robust features are defined by the non-robust features ResNet-50 captures,
NRFresnetNRF_{resnet}

Notice how far back VGG is compared to the other models.

In the unrelated field of neural style transfer, VGG-based neural networks are also quite special since non-VGG architectures are
known to not work very well This phenomenon is discussed at length in this
Reddit thread.
without some sort of parameterization trick .
The above interpretation of the graph provides an alternative explanation for this phenomenon.
Since VGG is unable to capture non-robust features as well as other architectures, the outputs for style
transfer actually look more correct to humans!

To follow this argument, note that the perceptual losses used in neural style transfer are
dependent on matching features learned by a separately trained image classifier. If these learned
features don’t make sense to humans (non-robust features), the outputs for neural style transfer won’t
make sense either.

Before proceeding, let’s quickly discuss the results obtained by Mordvintsev, et. al. in Differentiable Image
Parameterizations, where they show that non-VGG architectures can work for style transfer by using a
simple technique previously established in feature visualization.
In their experiment, instead of optimizing the output image in RGB space, they optimize it in Fourier space,
and run the image through a series of transformations (e.g jitter, rotation, scaling) before passing it
through the neural network.

Can we reconcile this result with our hypothesis linking neural style transfer and non-robust features?

One possible theory is that all of these image transformations weaken or even destroy
non-robust features.
Since the optimization can no longer reliably manipulate non-robust features to bring down the loss, it is
forced to use robust features instead, which are presumably more resistant to the applied image
transformations (a rotated and jittered flappy ear still looks like a flappy ear).

A quick experiment

Testing our hypothesis is fairly straightforward:
Use an adversarially robust classifier for neural style transfer and see
what happens.

I evaluated a regularly trained (non-robust) ResNet-50 with a robustly trained ResNet-50 from Engstrom, et.
al. on their performance on neural style transfer.
For comparison, I performed the same algorithm with a regular VGG-19
 .

To ensure a fair comparison despite the different networks having different optimal hyperparameters, I
performed a small grid search for each image and manually picked the best output per network.
Further details can be read in a footnote

L-BFGS was used for optimization as it showed faster convergence
over Adam.
For ResNet-50, the style layers used were the ReLu outputs after each of the 4 residual blocks,
[relu2_x,relu3_x,relu4_x,relu5_x][relu2\_x, relu3\_x, relu4\_x, relu5\_x] while the content layer used was relu4_xrelu4\_x.
For VGG-19, style layers [relu1_1,relu2_1,relu3_1,relu4_1,relu5_1][relu1\_1,relu2\_1,relu3\_1,relu4\_1,relu5\_1] were used with a content layer
relu4_2relu4\_2.
In VGG-19, max pooling layers were replaced with avg pooling layers, as stated in Gatys, et. al.

or observed in the accompanying Colaboratory notebook.

The results of this experiment can be explored in the diagram below.

Success!
The robust ResNet shows drastic improvement over the regular ResNet.
Remember, all we did was switch the ResNet’s weights, the rest of the code for performing style transfer is
exactly the same!

A more interesting comparison can be done between VGG-19 and the robust ResNet.
At first glance, the robust ResNet’s outputs seem on par with VGG-19.
Looking closer, however, the ResNet’s outputs seem slightly noisier and exhibit some artifacts
This is more obvious when the output image is initialized not with the content image, but with
Gaussian noise.
.

Texture synthesized with VGG.
Mild artifacts.

Texture synthesized with robust ResNet.
Severe artifacts.

A comparison of artifacts between textures synthesized by VGG and ResNet.
Interact by hovering around the images.
This diagram was repurposed from

Deconvolution and Checkerboard Artifacts

by Odena, et. al.

It is currently unclear exactly what causes these artifacts.
One theory is that they are checkerboard artifacts
caused by
non-divisible kernel size and stride in the convolution layers.
They could also be artifacts caused by the presence of max pooling layers
in ResNet.
An interesting implication is that these artifacts, while problematic, seem orthogonal to the
problem that
adversarial robustness solves in neural style transfer.

VGG remains a mystery

Although this experiment started because of an observation about a special characteristic of VGG
nets, it
did not provide an explanation for this phenomenon.
Indeed, if we are to accept the theory that adversarial robustness is the reason VGG works out of
the box
with neural style transfer, surely we’d find some indication in existing literature that VGG is
naturally
more robust than other architectures.

A few papers
indeed show
that VGG architectures are slightly more robust than ResNet.
However, they also show that AlexNet, not known to work well
for
neural style transferAs shown by Dávid Komorowicz
in
this blog post.
, is
above VGG in terms of this “natural robustness”.

Perhaps adversarial robustness just happens to incidentally fix or cover up the true reason non-VGG
architectures fail at style transfer (or other similar algorithms

In fact, neural style transfer is not the only pretrained classifier-based iterative image
optimization
technique that magically works better with adversarial robustness. In Engstrom, et. al., they show that feature visualization via activation
maximization works on robust classifiers without
enforcing
any priors or regularization (e.g. image transformations and decorrelated parameterization) used
by
previous work. In a recent chat with Chris
Olah, he
pointed out that the aforementioned feature visualization techniques actually work well on VGG
without these priors, just like style transfer!

) i.e. adversarial robustness is a sufficient but unnecessary condition for good style transfer.
Whatever the reason, I believe that further examination of VGG is a very interesting direction for
future
work.

Response Summary: Very interesting
results, highlighting the effect of non-robust features and the utility of
robust models for downstream tasks. We’re excited to see what kind of impact
robustly trained models will have in neural network art! We were also really
intrigued by the mysteriousness of VGG in the context of style transfer
. As such, we took a
deeper dive which found some interesting links between robustness and style
transfer that suggest that perhaps robustness does indeed play a role here.

Response: These experiments are really cool! It is interesting that
preventing the reliance of a model on non-robust features improves performance
on style transfer, even without an explicit task-related objective (i.e. we
didn’t train the networks to be better for style transfer).

We also found the discussion of VGG as a “mysterious network” really
interesting — it would be valuable to understand what factors drive style transfer
performance more generally. Though not a complete answer, we made a couple of
observations while investigating further:

Style transfer does work with AlexNet: One wrinkle in the idea that
robustness is the “secret ingredient” to style transfer could be that VGG is not
the most naturally robust network — AlexNet is. However, based on our own
testing, style transfer does seem to work with AlexNet out-of-the-box, as
long as we use a few early layers in the network (in a similar manner to
VGG):

Style transfer using AlexNet, using conv_1 through conv_4.

Observe that even though style transfer still works, there are checkerboard
patterns emerging — this seems to be a similar phenomenon to the one noticed
in the comment in the context of robust models.
This might be another indication that these two phenomena (checkerboard
patterns and style transfer working) are not as intertwined as previously
thought.

From prediction robustness to layer robustness: Another
potential wrinkle here is that both AlexNet and VGG are not that
much more robust than ResNets (for which style transfer completely fails),
and yet seem to have dramatically better performance. To try to
explain this, recall that style transfer is implemented as a minimization of a
combined objective consisting of a style loss and a content loss. We found,
however, that the network we use to compute the
style loss is far more important
than the one for the content loss. The following demo illustrates this — we can
actually use a non-robust ResNet for the content loss and everything works just
fine:

Style transfer seems to be rather
invariant to the choice of content network used, and very sensitive
to the style network used.

Therefore, from now on, we use a fixed ResNet-50 for the content loss as a
control, and only worry about the style loss.

Now, note that the way that style loss works is by using the first few
layers of the relevant network. Thus, perhaps it is not about the robustness of
VGG’s predictions, but instead about the robustness of the layers that we actually use
for style transfer?

To test this hypothesis, we measure the robustness of a layer ff as:

R(f)=Ex1∼D[maxx′∥f(x′)−f(x1)∥2]Ex1,x2∼D[∥f(x1)−f(x2)∥2] R(f) = \frac{\mathbb{E}_{x_1\sim D}\left[\max_{x’} \|f(x’) – f(x_1)\|_2 \right]} {\mathbb{E}_{x_1, x_2 \sim D}\left[\|f(x_1) – f(x_2)\|_2\right]}

Essentially, this quantity tells us how much we can change the
output of that layer f(x)f(x) within a small ball, normalized by how far apart
representations are between images in general. We’ve plotted this value for
the first few layers in a couple of different networks below:

The robustness R(f)R(f) of the first
four layers of VGG16, AlexNet, and robust/standard ResNet-50
trained on ImageNet.

Here, it becomes clear that, the first few layers of VGG and AlexNet are
actually almost as robust as the first few layers of the robust ResNet!
This is perhaps a more convincing indication that robustness might have
something to with VGG’s success in style transfer after all.

Finally, suppose we restrict style transfer to only use a single layer of
the network when computing the style lossUsually style transfer uses
several layers in the loss function to get the most visually appealing results — here we’re only interested in whether or not style transfer works (i.e.
actually confers some style onto the image).
. Again, the more
robust layers seem to indeed work better for style transfer! Since all of the
layers in the robust ResNet are robust, style transfer yields non-trivial
results even using the last layer alone. Conversely, VGG and AlexNet seem to
excel in the earlier layers (where they are non-trivially robust) but fail when
using exclusively later (non-robust) layers:


Style transfer using a single layer. The
names of the layers and their robustness R(f)R(f) are printed below
each style transfer result. We find that for both networks, the robust
layers seem to work (for the robust ResNet, every layer is robust).

Of course, there is much more work to be done here, but we are excited
to see further work into understanding the role of both robustness and the VGG
in network-based image manipulation.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

阿根廷对阵布基纳法索 阿根廷 - 布基纳法索 阿根廷对阵 阿根廷 阿根廷国家足球队 布基纳法索国家足球队 阿根廷国家足球队对阵布基纳法索国家足球队阵容 阿根廷比赛 哪里观看阿根廷国家足球队对阵布基纳法索国家足球队的比赛 阿根廷对阵布基纳法索 俄亥俄州立大学对阵爱荷华大学 爱荷华大学对阵俄亥俄州立大学 爱荷华大学橄榄球 杰里迈亚·史密斯 (Jeremiah Smith) 杰里迈亚·史密斯数据 爱荷华大学 俄亥俄州立大学 OSU对阵爱荷华大学 朱利安·萨因 (Julian Sayin) 爱荷华大学比赛 俄亥俄州立大学 爱荷华大学 俄亥俄州立大学七叶树队 (Buckeyes) 橄榄球 俄亥俄州立大学比分 爱荷华大学比分 俄亥俄州立大学七叶树队对阵爱荷华大学鹰眼队 (Hawkeyes) 比赛球员数据 俄亥俄州立大学七叶树队 七叶树队橄榄球 鹰眼队橄榄球 柯克·费伦茨 (Kirk Ferentz) 汉克·布朗 (Hank Brown) 俄亥俄州立大学橄榄球赛程 贾科比·杰克逊 (Ja'Kobi Jackson) 爱荷华大学鹰眼队 俄亥俄州立大学比赛在哪个频道播出 哪里观看俄亥俄州立大学七叶树队对阵爱荷华大学鹰眼队的橄榄球比赛 今天俄亥俄州立大学比赛在哪个频道播出 教士队 (Padres) 对阵酿酒人队 (Brewers) 酿酒人队 酿酒人队比赛 密尔沃基酿酒人队 酿酒人队对阵教士队 酿酒人队比分 教士队 教士队比赛 教士队今日比赛 酿酒人队今日比赛 圣地亚哥教士队 泰·弗朗斯 (Ty France) 曼尼·马查多 (Manny Machado) 威廉·孔特雷拉斯 (William Contreras) 密尔沃基 教士队 - 酿酒人队 教士队比分 特雷弗·梅吉尔 (Trevor Megill) 酿酒人队赛程 教士队 酿酒人队 梅吉尔 酿酒人队 酿酒人队比赛 酿酒人队 教士队 孔特雷拉斯 酿酒人队 教士队对阵密尔沃基酿酒人队 今日MLB比赛 Baseball Savant Lucki Lucki被刺伤 Lucki被刺伤了吗 说唱歌手Lucki Lucki遇刺事件 美国 - 墨西哥 墨西哥对阵美国 墨西哥国家队 美国对阵墨西哥 迭戈·坎皮略 (Diego Campillo) 墨西哥国家足球队 劳尔·兰赫尔 (Raúl Rangel) 友谊赛 路易斯·罗莫 (Luis Romo) 墨西哥何时比赛 墨西哥对阵美国 美国美国对墨西哥 墨西哥对阵 奥尔贝林·皮内达 迈阿密(佛罗里达州)对克莱姆森 迈阿密橄榄球 克莱姆森对迈阿密 迈阿密对克莱姆森 迈阿密飓风队 迈阿密飓风队橄榄球 达里安·门萨 迈阿密 迈阿密-克莱姆森 迈阿密大学橄榄球 克莱姆森-迈阿密 库珀·巴卡特 迈阿密对克莱姆森预测 麦克尼斯州立大学对LSU LSU对麦克尼斯 麦克尼斯橄榄球 LSU今日比赛 麦克尼斯 勇士队对道奇队 道奇队今日比赛 塔里克·斯库巴尔 道奇队赛程 勇士队今日比赛 斯库巴尔 亚特兰大勇士队对道奇队 扬基队对光芒队 德鲁·拉斯穆森 扬基队 扬基队今日比赛 坦帕湾光芒队 光芒队 扬基队比赛 纽约扬基队 扬基队今日比赛 光芒队比赛 扬基队比赛 光芒队今日比赛 NYY 扬基队-光芒队 奥斯汀·威尔斯 纽约扬基队 扬基队 阿肯色大学对德州农工大学 德州农工大学橄榄球 德州理工大学对科罗拉多大学 德州理工大学橄榄球 迪昂·桑德斯 科罗拉多大学橄榄球 德州理工大学 科罗拉多大学对德州理工大学 科罗拉多大学水牛队橄榄球 아르헨티나 대 부르키나파소 아르헨티나 - 부르키나파소 아르헨티나 대 아르헨티나 아르헨티나 축구 국가대표팀 부르키나파소 축구 국가대표팀 아르헨티나 대 부르키나파소 축구 국가대표팀 선발 명단 아르헨티나 경기 아르헨티나 대 부르키나파소 축구 국가대표팀 경기 중계 정보 아르헨티나 대 부르키나파소 오하이오 주립대 대 아이오와대 아이오와대 대 오하이오 주립대 아이오와대 미식축구 제레미아 스미스 제레미아 스미스 기록 아이오와대 오하이오 주립대 OSU 대 아이오와대 줄리안 세이인 아이오와대 경기 오하이오 주립대 아이오와대 오하이오 주립대 버키스 미식축구 오하이오 주립대 점수 아이오와대 점수 오하이오 주립대 버키스 대 아이오와대 호키스 미식축구 경기 선수 기록 오하이오 주립대 버키스 버키스 미식축구 호키스 미식축구 커크 페렌츠 행크 브라운 오하이오 주립대 미식축구 일정 자코비 잭슨 아이오와대 호키스 오하이오 주립대 경기 중계 채널 오하이오 주립대 버키스 대 아이오와대 호키스 미식축구 경기 시청 방법 오늘 오하이오 주립대 경기 중계 채널 파드리스 대 브루어스 브루어스 브루어스 경기 밀워키 브루어스 브루어스 대 파드리스 브루어스 점수 파드리스 파드리스 경기 오늘 파드리스 경기 오늘 브루어스 경기 샌디에이고 파드리스 타이 프랑스 매니 마차도 윌리엄 콘트레라스 밀워키 파드리스 - 브루어스 파드리스 점수 트레버 메길 브루어스 일정 파드리스 브루어스 메길 브루어스 브루어스 경기 브루어스 파드리스 콘트레라스 브루어스 파드리스 대 밀워키 브루어스 오늘 MLB 경기 베이스볼 사반트 럭키(Lucki) 럭키 피습 럭키가 칼에 찔렸나요? 래퍼 럭키 럭키 피습 사건 미국 - 멕시코 멕시코 대 미국 멕시코 국가대표팀 미국 대 멕시코 디에고 캄필로 멕시코 축구 국가대표팀 라울 랑헬 친선 경기 루이스 로모 멕시코 경기 일정 멕시코 대 미국 미국 미국 대 멕시코 멕시코 대 오르벨린 피네다 마이애미 대 클렘슨 마이애미 풋볼 클렘슨 대 마이애미 마이애미 대 클렘슨 마이애미 허리케인스 마이애미 허리케인스 풋볼 다리안 멘사 마이애미 마이애미 클렘슨 UM 풋볼 클렘슨 마이애미 쿠퍼 바케이트 마이애미 대 클렘슨 경기 예측 맥니스 주립대 대 LSU LSU 대 맥니스 맥니스 풋볼 오늘 LSU 경기 맥니스 브레이브스 대 다저스 오늘 다저스 경기 타릭 스쿠발 다저스 일정 오늘 브레이브스 경기 스쿠발 애틀랜타 브레이브스 대 다저스 양키스 대 레이스 드류 라스무센 양키스 오늘 양키스 경기 탬파베이 레이스 레이스 양키스 경기 뉴욕 양키스 오늘 양키스 경기 레이스 경기 양키스 경기 오늘 레이스 경기 NYY 양키스 레이스 오스틴 웰스 NY 양키스 양키 아칸소 대 텍사스 A&M A&M 풋볼 텍사스 공대 대 콜로라도 텍사스 공대 풋볼 디온 샌더스 CU 풋볼 텍사스 공대 콜로라도 대 텍사스 공대 CU 버프스 풋볼 アルゼンチン対ブルキナファソ アルゼンチン - ブルキナファソ アルゼンチン対 アルゼンチン アルゼンチン代表(サッカー) ブルキナファソ代表(サッカー) アルゼンチン代表対ブルキナファソ代表の出場メンバー アルゼンチンの試合 アルゼンチン代表対ブルキナファソ代表の視聴方法 アルゼンチン対ブルキナファソ オハイオ州立大対アイオワ大 アイオワ大対オハイオ州立大 アイオワ大フットボール ジェレマイア・スミス ジェレマイア・スミスの成績 アイオワ大・オハイオ州立大 OSU対アイオワ大 ジュリアン・サイン アイオワ大の試合 オハイオ州立大・アイオワ大 オハイオ州立大バッカイズ・フットボール オハイオ州立大のスコア アイオワ大のスコア オハイオ州立大バッカイズ対アイオワ大ホークアイズの試合・選手成績 オハイオ州立大バッカイズ バッカイズ・フットボール ホークアイズ・フットボール カーク・フェレンツ ハンク・ブラウン オハイオ州立大フットボールの日程 ジャコビ・ジャクソン アイオワ大ホークアイズ オハイオ州立大の試合の放送チャンネル オハイオ州立大バッカイズ対アイオワ大ホークアイズの視聴方法 今日のオハイオ州立大の試合の放送チャンネル パドレス対ブルワーズ ブルワーズ ブルワーズの試合 ミルウォーキー・ブルワーズ ブルワーズ対パドレス ブルワーズのスコア パドレス パドレスの試合 今日のパドレスの試合 今日のブルワーズの試合 サンディエゴ・パドレス タイ・フランス マニー・マチャド ウィリアム・コントレラス ミルウォーキー パドレス - ブルワーズ パドレスのスコア トレバー・メギル ブルワーズの日程 パドレス・ブルワーズ メギル・ブルワーズ ブルワーズの試合 ブルワーズ・パドレス コントレラス・ブルワーズ パドレス対ミルウォーキー・ブルワーズ 今日のMLBの試合 ベースボール・サバント Lucki Lucki 刺される Luckiは刺されたのか ラッパー Lucki Lucki 刺傷事件 アメリカ対メキシコ メキシコ対アメリカ メキシコ代表 アメリカ対メキシコ ディエゴ・カンピージョ メキシコ代表(サッカー) ラウル・ランヘル 親善試合 ルイス・ロモ メキシコの試合日程 メキシコ対USA アメリカ米国対メキシコ メキシコ対 オルベリン・ピネダ マイアミ対クレムソン マイアミ・フットボール クレムソン対マイアミ マイアミ対クレムソン マイアミ・ハリケーンズ マイアミ・ハリケーンズ・フットボール ダリアン・メンサ マイアミ マイアミ・クレムソン UMフットボール クレムソン・マイアミ クーパー・バーケイト マイアミ対クレムソン 予想 マクニース州立大対LSU LSU対マクニース マクニース・フットボール LSUの今日の試合 マクニース ブレーブス対ドジャース ドジャースの今日の試合 タリク・スクーバル ドジャースの日程 ブレーブスの今日の試合 スクーバル アトランタ・ブレーブス対ドジャース ヤンキース対レイズ ドリュー・ラスムッセン ヤンキース ヤンキースの今日の試合 タンパベイ・レイズ レイズ ヤンキースの試合 ニューヨーク・ヤンキース ヤンキースの今日の試合 レイズの試合 ヤンキースの試合 レイズの今日の試合 NYY