Interactive analysis of CNN robustness

Sietzen S, Lechner M, Borowski J, Hasani R, Waldner M. 2021. Interactive analysis of CNN robustness. Computer Graphics Forum. 40(7), 253–264.


Journal Article | Published | English

Scopus indexed
Author
Sietzen, Stefan; Lechner, MathiasISTA; Borowski, Judy; Hasani, Ramin; Waldner, Manuela
Abstract
While convolutional neural networks (CNNs) have found wide adoption as state-of-the-art models for image-related tasks, their predictions are often highly sensitive to small input perturbations, which the human vision is robust against. This paper presents Perturber, a web-based application that allows users to instantaneously explore how CNN activations and predictions evolve when a 3D input scene is interactively perturbed. Perturber offers a large variety of scene modifications, such as camera controls, lighting and shading effects, background modifications, object morphing, as well as adversarial attacks, to facilitate the discovery of potential vulnerabilities. Fine-tuned model versions can be directly compared for qualitative evaluation of their robustness. Case studies with machine learning experts have shown that Perturber helps users to quickly generate hypotheses about model vulnerabilities and to qualitatively compare model behavior. Using quantitative analyses, we could replicate users’ insights with other CNN architectures and input images, yielding new insights about the vulnerability of adversarially trained models.
Publishing Year
Date Published
2021-11-27
Journal Title
Computer Graphics Forum
Acknowledgement
We thank Robert Geirhos and Roland Zimmermann for their participation in the case study and valuable feedback, Chris Olah and Nick Cammarata for valuable discussions in the early phase of the project, as well as the Distill Slack workspace as a platform for discussions. M.L. is supported in part by the Austrian Science Fund (FWF) under grant Z211-N23 (Wittgenstein Award). J.B. is supported by the German Federal Ministry of Education and Research (BMBF) through the Competence Center for Machine Learning (TUE.AI, FKZ 01IS18039A) and the International Max Planck Research School for Intelligent Systems (IMPRS-IS). R.H. is partially supported by Boeing and Horizon-2020 ECSEL (grant 783163, iDev40).
Volume
40
Issue
7
Page
253-264
ISSN
eISSN
IST-REx-ID

Cite this

Sietzen S, Lechner M, Borowski J, Hasani R, Waldner M. Interactive analysis of CNN robustness. Computer Graphics Forum. 2021;40(7):253-264. doi:10.1111/cgf.14418
Sietzen, S., Lechner, M., Borowski, J., Hasani, R., & Waldner, M. (2021). Interactive analysis of CNN robustness. Computer Graphics Forum. Wiley. https://doi.org/10.1111/cgf.14418
Sietzen, Stefan, Mathias Lechner, Judy Borowski, Ramin Hasani, and Manuela Waldner. “Interactive Analysis of CNN Robustness.” Computer Graphics Forum. Wiley, 2021. https://doi.org/10.1111/cgf.14418.
S. Sietzen, M. Lechner, J. Borowski, R. Hasani, and M. Waldner, “Interactive analysis of CNN robustness,” Computer Graphics Forum, vol. 40, no. 7. Wiley, pp. 253–264, 2021.
Sietzen S, Lechner M, Borowski J, Hasani R, Waldner M. 2021. Interactive analysis of CNN robustness. Computer Graphics Forum. 40(7), 253–264.
Sietzen, Stefan, et al. “Interactive Analysis of CNN Robustness.” Computer Graphics Forum, vol. 40, no. 7, Wiley, 2021, pp. 253–64, doi:10.1111/cgf.14418.
All files available under the following license(s):
Copyright Statement:
This Item is protected by copyright and/or related rights. [...]

Link(s) to Main File(s)
Access Level
OA Open Access

Export

Marked Publications

Open Data ISTA Research Explorer

Web of Science

View record in Web of Science®

Sources

arXiv 2110.07667

Search this title in

Google Scholar