about
Intriguing Properties of Neural Networks [pdf] (arxiv.org)
19 points by jeremynixon on Feb 4, 2015 | hide | past | pdf | 4 comments on HN

In plain words: Probing image- and speech-recognition networks, the study found random mixes of a layer's neurons explain its knowledge as well as single neurons do. It also showed imperceptible tweaks to an image can flip the answer, and the same tweak fools a separately trained network.

Abstract · Intriguing properties of neural networks

Deep neural networks are highly expressive models that have recently achieved state of the art performance on speech and visual recognition tasks. While their expressiveness is the reason they succeed, it also causes them to learn uninterpretable solutions that could have counter-intuitive properties. In this paper we report two such properties. First, we find that there is no distinction between individual high level units and random linear combinations of high level units, according to various methods of unit analysis. It suggests that it is the space, rather than the individual units, that contains of the semantic information in the high layers of neural networks. Second, we find that deep neural networks learn input-output mappings that are fairly discontinuous to a significant extend. We can cause the network to misclassify an image by applying a certain imperceptible perturbation, which is found by maximizing the network's prediction error. In addition, the specific nature of these perturbations is not a random artifact of learning: the same perturbation can cause a different network, that was trained on a different subset of the dataset, to misclassify the same input.

Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, Rob Fergus
arXiv:1312.6199 · cs.CV, cs.LG, cs.NE · submitted Dec 21, 2013 · updated Feb 19, 2014
abstract · pdf · html

add comment on HN
Also discussed: Jan 2019 (2 points, 0 comments) · Jan 2015 (1 point, 0 comments)

The reason the Neural Networks are suffering from blindspots is because they were never trained as generative models. A straightforward classifier cannot be expected to correctly identify something it has never seen before---so of course you can find adversary examples. Generative models are computationally more expensive to build, which is why they are not always used.
This paper demonstrates that deep neural networks have surprising blind spots when inputs are only slightly perturbed in a certain manner.

I wonder if these algorithmically determined adversarial examples can be fed back into the network in the training set with correct tagging to make the network more robust with regard to blind spots?

I think the problem will remain because the "bits" (perceptrons etc.) of representation are always less than the sum of the inputs. So the training is lossy, which also means not perfect.

As humans, we probably have less "blindspots" because we have learned extra double checking mechanisms, such as applying logic and our world knowledge to analyzing an image. We still fall prey to optical illusions though.

That's a good idea but there's other papers where they try that. Note that this paper is almost a year old now.