{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T22:34:03Z","timestamp":1777502043197,"version":"3.51.4"},"update-to":[{"DOI":"10.1371\/journal.pcbi.1010932","type":"new_version","label":"New version","source":"publisher","updated":{"date-parts":[[2023,4,6]],"date-time":"2023-04-06T00:00:00Z","timestamp":1680739200000}}],"reference-count":35,"publisher":"Public Library of Science (PLoS)","issue":"3","license":[{"start":{"date-parts":[[2023,3,27]],"date-time":"2023-03-27T00:00:00Z","timestamp":1679875200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100011039","name":"Intelligence Advanced Research Projects Activity","doi-asserted-by":"publisher","award":["D16PC00003"],"award-info":[{"award-number":["D16PC00003"]}],"id":[{"id":"10.13039\/100011039","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000053","name":"National Eye Institute","doi-asserted-by":"publisher","award":["R01EY026927"],"award-info":[{"award-number":["R01EY026927"]}],"id":[{"id":"10.13039\/100000053","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000053","name":"National Eye Institute","doi-asserted-by":"publisher","award":["EY-002520-37"],"award-info":[{"award-number":["EY-002520-37"]}],"id":[{"id":"10.13039\/100000053","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NeuroNex","award":["1707400"],"award-info":[{"award-number":["1707400"]}]}],"content-domain":{"domain":["www.ploscompbiol.org"],"crossmark-restriction":false},"short-container-title":["PLoS Comput Biol"],"abstract":"<jats:p>Machine learning models have difficulty generalizing to data outside of the distribution they were trained on. In particular, vision models are usually vulnerable to adversarial attacks or common corruptions, to which the human visual system is robust. Recent studies have found that regularizing machine learning models to favor brain-like representations can improve model robustness, but it is unclear why. We hypothesize that the increased model robustness is partly due to the low spatial frequency preference inherited from the neural representation. We tested this simple hypothesis with several frequency-oriented analyses, including the design and use of hybrid images to probe model frequency sensitivity directly. We also examined many other publicly available robust models that were trained on adversarial images or with data augmentation, and found that all these robust models showed a greater preference to low spatial frequency information. We show that preprocessing by blurring can serve as a defense mechanism against both adversarial attacks and common corruptions, further confirming our hypothesis and demonstrating the utility of low spatial frequency information in robust object recognition.<\/jats:p>","DOI":"10.1371\/journal.pcbi.1010932","type":"journal-article","created":{"date-parts":[[2023,3,27]],"date-time":"2023-03-27T13:34:56Z","timestamp":1679924096000},"page":"e1010932","update-policy":"https:\/\/doi.org\/10.1371\/journal.pcbi.corrections_policy","source":"Crossref","is-referenced-by-count":22,"title":["Robust deep learning object recognition models rely on low frequency information in natural images"],"prefix":"10.1371","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4176-9687","authenticated-orcid":true,"given":"Zhe","family":"Li","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7061-1112","authenticated-orcid":true,"given":"Josue","family":"Ortega Caro","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6039-7781","authenticated-orcid":true,"given":"Evgenia","family":"Rusak","sequence":"additional","affiliation":[]},{"given":"Wieland","family":"Brendel","sequence":"additional","affiliation":[]},{"given":"Matthias","family":"Bethge","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0264-4761","authenticated-orcid":true,"given":"Fabio","family":"Anselmi","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9678-496X","authenticated-orcid":true,"given":"Ankit B.","family":"Patel","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4305-6376","authenticated-orcid":true,"given":"Andreas S.","family":"Tolias","sequence":"additional","affiliation":[]},{"given":"Xaq","family":"Pitkow","sequence":"additional","affiliation":[]}],"member":"340","published-online":{"date-parts":[[2023,3,27]]},"reference":[{"key":"pcbi.1010932.ref001","doi-asserted-by":"crossref","unstructured":"Girshick R. Fast r-cnn. In: Proceedings of the IEEE international conference on computer vision; 2015. p. 1440\u20131448.","DOI":"10.1109\/ICCV.2015.169"},{"key":"pcbi.1010932.ref002","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J. Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition; 2016. p. 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"pcbi.1010932.ref003","doi-asserted-by":"crossref","unstructured":"He K, Gkioxari G, Doll\u00e1r P, Girshick R. Mask r-cnn. In: Proceedings of the IEEE international conference on computer vision; 2017. p. 2961\u20132969.","DOI":"10.1109\/ICCV.2017.322"},{"key":"pcbi.1010932.ref004","unstructured":"Hendrycks D, Mu N, Cubuk ED, Zoph B, Gilmer J, Lakshminarayanan B. AugMix: A Simple Method to Improve Robustness and Uncertainty under Data Shift. In: International Conference on Learning Representations; 2020. Available from: https:\/\/openreview.net\/forum?id=S1gmrxHFvB."},{"key":"pcbi.1010932.ref005","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, et al. Intriguing properties of neural networks. arXiv preprint arXiv:13126199. 2013;."},{"key":"pcbi.1010932.ref006","unstructured":"Geirhos R, Janssen DH, Sch\u00fctt HH, Rauber J, Bethge M, Wichmann FA. Comparing deep neural networks against humans: object recognition when the signal gets weaker. arXiv e-prints. 2017;."},{"key":"pcbi.1010932.ref007","first-page":"9525","volume-title":"Advances in Neural Information Processing Systems 32","author":"Z Li","year":"2019"},{"key":"pcbi.1010932.ref008","volume-title":"Advances in Neural Information Processing Systems 34","author":"S Safarani","year":"2021"},{"key":"pcbi.1010932.ref009","first-page":"13073","volume-title":"Advances in Neural Information Processing Systems 33","author":"J Dapello","year":"2020"},{"key":"pcbi.1010932.ref010","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1007\/978-3-030-58580-8_4","volume-title":"Computer Vision \u2013 ECCV 2020","author":"E Rusak","year":"2020"},{"key":"pcbi.1010932.ref011","unstructured":"Geirhos R, Rubisch P, Michaelis C, Bethge M, Wichmann FA, Brendel W. ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness. In: International Conference on Learning Representations; 2019."},{"key":"pcbi.1010932.ref012","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. arXiv e-prints. 2017;."},{"key":"pcbi.1010932.ref013","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, El Ghaoui L, Jordan M. Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning. PMLR; 2019. p. 7472\u20137482."},{"key":"pcbi.1010932.ref014","unstructured":"Zhang R. Making convolutional networks shift-invariant again. In: International conference on machine learning. PMLR; 2019. p. 7324\u20137334."},{"key":"pcbi.1010932.ref015","first-page":"13276","volume-title":"Advances in Neural Information Processing Systems 32","author":"D Yin","year":"2019"},{"issue":"6","key":"pcbi.1010932.ref016","doi-asserted-by":"crossref","first-page":"967","DOI":"10.1016\/j.neuron.2019.08.034","article-title":"Engineering a less artificial intelligence","volume":"103","author":"FH Sinz","year":"2019","journal-title":"Neuron"},{"key":"pcbi.1010932.ref017","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.neunet.2020.07.013","article-title":"Improved object recognition using neural networks trained to mimic the brain\u2019s statistical properties","volume":"131","author":"C Federer","year":"2020","journal-title":"Neural Networks"},{"issue":"7765","key":"pcbi.1010932.ref018","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1038\/s41586-019-1346-5","article-title":"High-dimensional geometry of population responses in visual cortex","volume":"571","author":"C Stringer","year":"2019","journal-title":"Nature"},{"key":"pcbi.1010932.ref019","first-page":"4","article-title":"Representational similarity analysis\u2014connecting the branches of systems neuroscience","volume":"2","author":"N Kriegeskorte","year":"2008","journal-title":"Frontiers in Systems Neuroscience"},{"key":"pcbi.1010932.ref020","first-page":"12861","volume-title":"Advances in Neural Information Processing Systems 32","author":"W Brendel","year":"2019"},{"issue":"7","key":"pcbi.1010932.ref021","first-page":"3","article-title":"Tiny ImageNet visual recognition challenge","volume":"7","author":"Y Le","year":"2015","journal-title":"CS 231N"},{"key":"pcbi.1010932.ref022","unstructured":"Hendrycks D, Dietterich T. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. In: International Conference on Learning Representations; 2019. Available from: https:\/\/openreview.net\/forum?id=HJz6tiCqYm."},{"issue":"3","key":"pcbi.1010932.ref023","doi-asserted-by":"crossref","first-page":"527","DOI":"10.1145\/1141911.1141919","article-title":"Hybrid Images","volume":"25","author":"A Oliva","year":"2006","journal-title":"ACM Trans Graph"},{"key":"pcbi.1010932.ref024","unstructured":"Croce F, Andriushchenko M, Sehwag V, Flammarion N, Chiang M, Mittal P, et al. RobustBench: a standardized adversarial robustness benchmark. arXiv e-prints. 2020;."},{"key":"pcbi.1010932.ref025","doi-asserted-by":"crossref","unstructured":"Bhagoji AN, Cullina D, Sitawarin C, Mittal P. Enhancing robustness of machine learning systems via data transformations. In: 2018 52nd Annual Conference on Information Sciences and Systems (CISS). IEEE; 2018. p. 1\u20135.","DOI":"10.1109\/CISS.2018.8362326"},{"key":"pcbi.1010932.ref026","doi-asserted-by":"crossref","unstructured":"Laugros A, Caplier A, Ospici M. Are adversarial robustness and common perturbation robustness independant attributes? In: Proceedings of the IEEE\/CVF International Conference on Computer Vision Workshops; 2019. p. 0\u20130.","DOI":"10.1109\/ICCVW.2019.00134"},{"issue":"1","key":"pcbi.1010932.ref027","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1167\/2.1.2","article-title":"Receptive field structure of neurons in monkey primary visual cortex revealed by stimulation with natural image sequences","volume":"2","author":"DL Ringach","year":"2002","journal-title":"Journal of Vision"},{"issue":"30","key":"pcbi.1010932.ref028","doi-asserted-by":"crossref","first-page":"7520","DOI":"10.1523\/JNEUROSCI.0623-08.2008","article-title":"Highly Selective Receptive Fields in Mouse Visual Cortex","volume":"28","author":"CM Niell","year":"2008","journal-title":"Journal of Neuroscience"},{"key":"pcbi.1010932.ref029","doi-asserted-by":"crossref","first-page":"2051","DOI":"10.1002\/cne.22321","article-title":"Receptive-field properties of V1 and V2 neurons in mice and macaque monkeys","volume":"518","author":"G Van den Bergh","year":"2010","journal-title":"The Journal of comparative neurology"},{"key":"pcbi.1010932.ref030","unstructured":"Caro JO, Ju Y, Pyle R, Dey S, Brendel W, Anselmi F, et al. Local convolutions cause an implicit bias towards high frequency adversarial examples. arXiv preprint arXiv:200611440. 2020;."},{"key":"pcbi.1010932.ref031","unstructured":"Vasconcelos C, Larochelle H, Dumoulin V, Roux NL, Goroshin R. An effective anti-aliasing approach for residual networks. arXiv e-prints. 2020;."},{"key":"pcbi.1010932.ref032","first-page":"274","volume-title":"vol. 80 of Proceedings of Machine Learning Research","author":"A Athalye","year":"2018"},{"issue":"1","key":"pcbi.1010932.ref033","first-page":"1","article-title":"Increasing neural network robustness improves match to macaque V1 eigenspectrum, spatial frequency preference and predictivity","volume":"18","author":"NCL Kong","year":"2022","journal-title":"PLOS Computational Biology"},{"issue":"53","key":"pcbi.1010932.ref034","doi-asserted-by":"crossref","first-page":"2607","DOI":"10.21105\/joss.02607","article-title":"Foolbox Native: Fast adversarial attacks to benchmark the robustness of machine learning models in PyTorch, TensorFlow, and JAX","volume":"5","author":"J Rauber","year":"2020","journal-title":"Journal of Open Source Software"},{"key":"pcbi.1010932.ref035","unstructured":"Rauber J, Brendel W, Bethge M. Foolbox: A Python toolbox to benchmark the robustness of machine learning models. In: Reliable Machine Learning in the Wild Workshop, 34th International Conference on Machine Learning; 2017. Available from: http:\/\/arxiv.org\/abs\/1707.04131."}],"updated-by":[{"DOI":"10.1371\/journal.pcbi.1010932","type":"new_version","label":"New version","source":"publisher","updated":{"date-parts":[[2023,4,6]],"date-time":"2023-04-06T00:00:00Z","timestamp":1680739200000}}],"container-title":["PLOS Computational Biology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dx.plos.org\/10.1371\/journal.pcbi.1010932","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,6]],"date-time":"2023-04-06T13:55:21Z","timestamp":1680789321000},"score":1,"resource":{"primary":{"URL":"https:\/\/dx.plos.org\/10.1371\/journal.pcbi.1010932"}},"subtitle":[],"editor":[{"given":"Xue-Xin","family":"Wei","sequence":"first","affiliation":[]}],"short-title":[],"issued":{"date-parts":[[2023,3,27]]},"references-count":35,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2023,3,27]]}},"URL":"https:\/\/doi.org\/10.1371\/journal.pcbi.1010932","relation":{"has-preprint":[{"id-type":"doi","id":"10.1101\/2022.01.31.478509","asserted-by":"object"}]},"ISSN":["1553-7358"],"issn-type":[{"value":"1553-7358","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,27]]}}}