发表机构
National Institute of Technology Rourkela(鲁尔克拉国家理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究探究分割模型的特征-频谱脆弱性,发现其具有强数据集依赖性与架构特异性,傅里叶增强可提升输入空间低通鲁棒性但不改变特征域退化。
AI 中文摘要
分割模型的鲁棒性通常通过输入域扰动进行评估,而对学习到的特征表示内的频率内容的依赖性却鲜为人知。我们针对三种分割架构(ResNet50-UNet(CNN)、VM-UNet(SSM)和Swin-UNETR(Transformer))的内部表示,采用训练后靶向低通干预来探究这种依赖性,实验在CVC-ClinicDB和ISIC2018两个数据集上开展,核心评估在未接触的保留测试集上进行。在截止值ρ=0.25时,特征域低通滤波在CVC上导致严重性能下降:与ISIC上的9.4%、10.3%和0.6%相比,CNN、SSM和Transformer的Dice分别下降100%、73.2%和30.9%;每种架构的跨数据集差异均具有统计学意义。单阶段干预进一步表明,敏感性定位于架构特定的深度:CNN在编码器的中/后期块达到峰值,而SSM在两个数据集上均在编码器早期阶段达到峰值。原生特征域频谱测量显示,CVC上高频能量与脆弱性呈负相关;该关系在ISIC上仅部分成立,因此被视为候选关联而非已证实的机制。最后,傅里叶增强可提升对输入空间低通滤波的鲁棒性,但基本不改变特征域的退化。这些结果表明,特征-频谱鲁棒性具有强数据集依赖性、架构特异性,且与输入域频谱鲁棒性不同。
英文摘要
Robustness of segmentation models is commonly assessed through input-domain perturbations, while dependence on frequency content within learned feature representations remains less understood. We probe this dependence using targeted post-training low-pass interventions on internal representations of three segmentation architectures, ResNet50-UNet (CNN), VM-UNet (SSM), and Swin-UNETR (Transformer), across CVC-ClinicDB and ISIC2018, with headline evaluations performed on untouched held-out test sets. At cutoff $ρ=0.25$, feature-domain low-pass filtering causes severe degradation on CVC: Dice drops by 100%, 73.2%, and 30.9% for CNN, SSM, and Transformer, respectively, compared with 9.4%, 10.3%, and 0.6% on ISIC. The cross-dataset difference is statistically significant for every architecture. Single-stage interventions further show that the most sensitive stage depends on architecture and dataset: the CNN peaks at the 2nd to 3rd encoder block, whereas the SSM peaks at the 1st to 2nd encoder stage. Native feature-domain spectral measurements show an inverse association between high-frequency energy and fragility on CVC; the relationship is only partial on ISIC and is therefore treated as a candidate correlate rather than a proven mechanism. Finally, Fourier augmentation improves robustness to input-space low-pass filtering but leaves feature-domain degradation essentially unchanged. These results show that feature-spectral robustness is strongly dataset-dependent, architecture-specific, and distinct from input-domain spectral robustness.
Comments4 pages, 3 figures