Related Experiment Video
Updated: Aug 29, 2025

Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications
Published on: December 15, 2023
Hierarchical binding in convolutional neural networks: Making adversarial attacks geometrically challenging.
Niels Leadholm1, Simon Stringer1
1The Oxford Centre for Theoretical Neuroscience and Artificial Intelligence, University of Oxford, Radcliffe Observatory Quarter, Oxford, OX2 6GG, United Kingdom.
This study introduces a novel deep-learning architecture inspired by primate brain visual processing to enhance machine vision robustness against adversarial examples. The new model shows improved defense capabilities, particularly in black-box scenarios.
Area of Science:
- Neuroscience
- Computer Vision
- Machine Learning
Background:
- Current deep learning models for machine vision are vulnerable to adversarial examples, which are subtle, often imperceptible image perturbations.
- This vulnerability may stem from the lack of explicit feature binding representations, unlike in the primate brain.
- Adversarial examples are theorized to arise from 'off-manifold' perturbations in image data.
Purpose of the Study:
- To develop a novel deep-learning architecture that improves machine vision robustness.
- To incorporate hierarchical feature binding mechanisms, inspired by primate visual neuroscience, into convolutional neural networks.
- To investigate the relationship between feature binding, representational geometry, and robustness against adversarial attacks.
Main Methods:
- Proposed a novel deep-learning architecture inspired by theoretical neuroscience on primate visual feature binding.
- Implemented hierarchical feature binding representations within convolutional neural networks.
- Empirically evaluated the architecture's robustness against various L0, L2, and Linf adversarial attacks, especially in black-box settings.
Main Results:
- The novel architecture demonstrated enhanced robustness against a range of adversarial attacks, particularly in the black-box setting.
- Analysis confirmed that the observed robustness was not due to gradient masking (false robustness).
- Representational geometry analysis revealed a positive correlation between hierarchical binding, expanded data manifolds, and robustness.
Conclusions:
- The proposed architecture, by approximating hierarchical feature binding, offers improved robustness in machine vision systems.
- Robustness appears to emerge from preserving both general low-level and abstract features.
- The findings suggest a potential link between hierarchical binding, human sensitivity to adversarial examples, and enhanced model robustness.
Related Concept Videos
Collisions in Multiple Dimensions: Introduction
Collisions in Multiple Dimensions: Problem Solving
A small car of mass 1,200 kg traveling east at 60 km/h collides at an intersection with a truck of mass 3,000 kg traveling due north at 40 km/h. The two vehicles are locked together. What is the...
Neural Circuits
Neuronal pools are collections of nerve cells with similar functions and interact through chemical and electrical signals. These pools include both interneurons (the central neural circuit nodes that...
Convolution Properties II
The width property indicates that if the durations of input signals are T1 and T2, then the width of the output response equals the sum of both durations, irrespective of the shapes of the two functions. For instance, convolving two rectangular pulses with durations of 2 seconds and 1 second results in a function with a width of 3 seconds.
The area property asserts that the area under the...
Convolution Properties I
The commutative property reveals that the input and the impulse response of an LTI (Linear Time-Invariant) system can be interchanged without affecting the output:
Convolution: Math, Graphics, and Discrete Signals
To simplify the convolution integral, it is assumed that both the input signal and impulse response are zero for negative time values. The graphical convolution process...
