ECCV 2022 - Proceedings of the 17th European Conference, Tel Aviv, Israel · 2022
FrequencyLowCut Pooling--Plug & Play against Catastrophic Overfitting
Why this publication matters
Fast robustness training is attractive, but it can suddenly lose nearly all of its protective effect. This paper tackles one cause by changing how a network reduces the resolution of its internal images. The replacement operation is designed to fit existing networks and makes this inexpensive training approach more stable.
Abstract
Over the last years, Convolutional Neural Networks (CNNs) have been the dominating neural architecture in a wide range of computer vision tasks. From an image and signal processing point of view, this success might be a bit surprising as the inherent spatial pyramid design of most CNNs is apparently violating basic signal processing laws, i.e. Sampling Theorem in their down-sampling operations. However, since poor sampling appeared not to affect model accuracy, this issue has been broadly neglected until model robustness started to receive more attention. Recent work [18] in the context of adversarial attacks and distribution shifts, showed after all, that there is a strong correlation between the vulnerability of CNNs and aliasing artifacts induced by poor downsampling operations. This paper builds on these findings and introduces an aliasing free down-sampling operation which can easily be plugged into any CNN architecture: FrequencyLowCut pooling. Our experiments show, that in combination with simple and Fast Gradient Sign Method (FGSM) adversarial training, our hyper-parameter free operator substantially improves model robustness and avoids catastrophic overfitting. Our code is available at https://github.com/GeJulia/flc_pooling
Figures
Cite this paper
@inproceedings{grabinski2022frequencylowcutpoolingplug17,
title = {{FrequencyLowCut Pooling--Plug \& Play against Catastrophic Overfitting}},
author = {Julia Grabinski and Steffen Jung and Janis Keuper and Margret Keuper},
booktitle = {European Conference on Computer Vision},
year = {2022},
url = {https://arxiv.org/pdf/2204.00491}
}
Figures and abstract are reproduced from the linked research sources. Credit remains with the authors and publishers.