On the Structural Sensitivity of Deep Convolutional Networks to the Directions of Fourier Basis Functions

  • 2018-09-11 18:23:09
  • Yusuke Tsuzuku, Issei Sato
  • 48

Abstract

Data-agnostic quasi-imperceptible perturbations on inputs can severelydegrade recognition accuracy of deep convolutional networks. This indicatessome structural instability of their predictions and poses a potential securitythreat. However, characterization of the shared directions of such harmfulperturbations remains unknown if they exist, which makes it difficult toaddress the security threat and performance degradation. Our primal finding isthat convolutional networks are sensitive to the directions of Fourier basisfunctions. We derived the property by specializing a hypothesis of the cause ofthe sensitivity, known as the linearity of neural networks, to convolutionalnetworks and empirically validated it. As a by-product of the analysis, wepropose a fast algorithm to create shift-invariant universal adversarialperturbations available in black-box settings.

 

Quick Read (beta)

loading the full paper ...