Pith. sign in

REVIEW 3 major objections 6 minor 39 references

Noninvasive precision modulation of high-level neural population activity via natural vision perturbations

T0 review · 3 major / 6 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Image perturbations designed by a neural network model can steer high-level monkey brain activity along experimenter-chosen directions, noninvasively and with limited off-target effects.

desk verdict Real monkey IT control via model-designed perturbations, but headline 'arbitrary direction' numbers come from a preselected favorable sample. read the letter →

arxiv 2506.05633 v3 pith:KNMQIHDT submitted 2025-06-05 q-bio.NC cs.CVcs.NE

classification q-bio.NCcs.CVcs.NE
keywords neuralmodulationinferiortemporalcortexventralstreammodeladversarialperturbationpopulationactivitycontrolnoninvasivebrainstimulationmodel-guidedimagedesignprimateelectrophysiology
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper asks whether current artificial neural network models of the primate ventral visual stream are accurate enough to design small, often imperceptible image perturbations that push the activity of a deep brain region, the inferior temporal (IT) cortex, in a predetermined direction. In macaque experiments, the authors report that these model-designed perturbations produce strong directional modulation, on average about 2.7 standard deviations of the natural operating range, while keeping activity in nearby non-targeted sites largely unchanged. They further show that a recognizable visual pattern, an institutional logo, can be injected into the measured population response through a sequence of perturbed natural images. If correct, this is the first demonstration of noninvasive, vision-delivered, precise neural population control in IT, pointing toward low-latency visual-feed augmentation as a potential tool for targeted brain-state modulation.

What carries the argument

The load-bearing machinery is a digital twin of the recorded IT population: an adversarially trained ResNet-50 feature extractor (layer 4.0) followed by a linear mapping regressed overnight to the recorded multi-unit IT sites, operating in a whitened 'canonical' neural space where sites have identity covariance. Perturbations are optimized by projected gradient descent using a loss that maximizes the change along the target direction (DM) while penalizing any orthogonal change (DOM) beyond a small budget. The same DM/DOM decomposition, computed in the canonical space, is used both for model guidance and for evaluating the biological effect, which is what lets the paper compare predicted and measured modulation quantitatively.

What would settle it

Re-run the two-day protocol using a mapping model whose regressed weights are randomly permuted after fitting but that still predicts the same DM on the held-out model validation set; if monkey-measured DM remains near 2.7 sigma rather than collapsing toward zero, then the model's gradient path across the mapping is not the carrier of the effect, and the central transfer claim is falsified.

Watch

Extended reading notes

Core claim

The paper's central claim is that a machine-executable model of the ventral stream, specifically an adversarially trained convolutional network whose high-level features are linearly mapped to recorded multi-unit IT sites, can generate base-image-contingent pixel perturbations that induce reliable, strong, directionally specific population activity changes in the biological IT cortex. Across six experiments in three macaques, the measured direction modulation (DM) averaged about 2.7 sigma, with DM-to-orthogonal-modulation ratios of 2.6:1 for single-frame and 4.9:1 for frame-averaged responses. The authors also show that the model's predictions rank-order which target directions are most 'available' for modulation, that image-contingent perturbations are necessary while fixed perturbations are not, and that a pseudo-natural saccade-like image sequence can carry an experimenter-chosen population pattern (the MIT logo) into the recorded neural responses. They characterize this as the first time population-level precise neural modulation has been measured in IT of any population size.

Load-bearing premise

The linear mapping from the adversarially trained model's layer-4.0 features to the recorded IT sites must preserve the causal relationship between small pixel perturbations and real biological responses, so that the gradients used to design perturbations actually point along effective directions in the monkey's IT space.

Editorial extensions

If this is right

  • If the central claim holds, then current ventral-stream models are sufficiently accurate to serve as engines for noninvasive, visually delivered neural control in a deep visual area.
  • The rank-order predictability of direction availability implies that some neural population states are far more addressable than others, so future interventions will need to choose target directions with model-based feasibility checks.
  • The image-contingent nature of effective perturbations means a practical system must compute each perturbation online from the current retinal input, which is plausible with low-latency augmented-reality delivery.
  • Because the measured orthogonal drift partially cancels across frames, downstream areas with integration timescales beyond roughly 200 ms should experience higher effective modulation efficiency than the single-frame numbers suggest.
  • The near-imperceptibility of potent perturbations supports a view of neural code degeneracy in IT, where many population states map to similar percepts.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A testable extension would be to measure whether the same perturbations alter behavior or percepts; if they do not, the method still achieves neural control but with no immediate perceptual consequence, which would constrain theories of IT's role in conscious vision.
  • The paper leaves open whether modulation scales to much larger IT populations; one could test this by mapping a larger set of sites or by using a model with higher-dimensional features and asking whether the DM/DOM ratio degrades gracefully.
  • Since the authors simulate a five-fold drop in measured efficiency from mapping noise alone, a natural next experiment is to reduce the mapping data set drastically and see whether measured DM falls proportionally, which would isolate the mapping as the main bottleneck.
  • The method may transfer beyond vision: any sensory modality with an accurate forward model could, in principle, be used to design input perturbations that steer high-level population activity along desired directions.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper presents a closed-loop, two-day protocol in which a linear mapping from an adversarially-trained ResNet-50 feature space (layer 4.0) to macaque inferior temporal (IT) multi-unit responses is used to generate per-image perturbations via projected gradient descent, with the goal of shifting the IT population state along an experimenter-chosen direction while limiting orthogonal drift. Across six experiments in three macaques, the authors report measured directional modulation (DM) generally exceeding direction-orthogonal modulation (DOM), with typical DM of 2.7 sigma and DM/DOM ratios of 2.6:1 (single-frame) and 4.9:1 (frame-average), and they show that a decomposition of the MIT logo can be injected into pseudo-natural viewing sequences. The authors conclude that current ventral-stream models can design noninvasive, visually delivered neural interventions, possibly imperceptible, at the resolution of individual neurons.

Significance. If the reported effects are robust, this is a notable advance: it would be the first demonstration that image-computable models of the ventral stream can drive population-level, directionally specific modulation in macaque IT using natural-image perturbations, with a credible path toward noninvasive interventions. Strengths include the two-day design with held-out base images and independent Day-2 measurements, careful noise corrections, multiple animals and populations, public code/data commitment, and a frank discussion of model overprediction. The authors also provide a useful negative result that image-fixed perturbations are predicted to be ineffective. The main quantitative claims, however, rely on direction selection that is not representative of 'arbitrary' directions, and several abstract claims exceed the multi-unit, visually-inspected evidence.

major comments (3)
  1. [Methods – Selecting non-cardinal directions; Fig. 4] The headline statistics are computed over a direction sample that is not representative of 'arbitrary experimenter-chosen directions.' Experiments 1–3 selected the eight most and two least predictively available directions from a 637-direction pool, and only Experiment 4 uniformly sampled ten directions; because predicted DM varies from roughly 4 sigma to 10 sigma across directions (Main Text), the pooled average DM of 2.7 sigma and the DM/DOM ratios of 2.6:1 and 4.9:1 are inflated by availability preselection. Please report the uniform-sample (Experiment 4) results separately, provide an availability-weighted or per-experiment breakdown, and state explicitly what the central tendency is for a randomly chosen direction. Also clarify whether the 50-image set used for availability ranking is the same as the 50 base images tested on Day 2; if so, the rank-order correlation in Fig. 4B is optimistically biased and needs a holdout analysis.
  2. [Abstract; Results – Fig. 4] The abstract's claim of 'quantitative agreement between the model-predicted and biologically realized effect' is contradicted by the main text and Fig. 4, which show that the model consistently overpredicts DM and by the authors' own simulation of a five-fold drop in modulation efficiency due to mapping noise. If 'quantitative agreement' is intended, please define the quantitative criterion; otherwise rephrase as qualitative or rank-order agreement.
  3. [Abstract; Methods – Electrophysiological recordings] The abstract states the method operates 'at the resolution of individual neurons' and produces 'possibly imperceptible' interventions. The recordings are multi-unit activity from Utah arrays (Methods: 'generally record multiple local neuronal responses per channel'), and imperceptibility is based on visual inspection of example images, not on psychophysical measurement. Please revise these claims to refer to multi-unit sites and to describe the perturbations as visually subtle, with an explicit caveat that perceptual awareness was not measured.
minor comments (6)
  1. [Throughout] The token '⁄tildelow' appears as a corrupted symbol (e.g., '⁄tildelow60', '⁄tildelow180 ms', '⁄tildelow200 ms'); please replace it with the intended approximation symbol or word.
  2. [Main Text, page 4] In the sentence 'we here tested (⁄tildelow60) arbitrarily chosen ones,' the exact number is unclear; please state the sample size explicitly.
  3. [References, ref 36] Reference 36 (ILSVRC) is missing author and title information; please provide a complete citation.
  4. [Results, cardinal modulation] The phrase 'within the ranges, 54-294, 78-223 and 27-164 spikes/s' uses a comma before the ranges; use a colon or rephrase for clarity.
  5. [Fig. 5B] The mapping from the 11 column-wise modulation directions to the six-dimensional IT space is unclear from the figure; please add a schematic or legend entry explaining the decomposition.
  6. [Methods – Noise corrections] The noise-correction procedure subtracts squared DOM contributions in variance units; please state explicitly in the main text (not only in the supplement) how the frame-average correction differs for the mean DOM vector, since this is central to the 4.9:1 ratio.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the monkey-measured DM/DOM on held-out base images is an independent external benchmark, and the model's overprediction shows the empirical result is not forced by the optimization objective.

full rationale

The derivation chain is self-contained: Day-1 IT responses are used only to fit a linear readout from a fixed, pretrained robustified ResNet-50; on Day-2, perturbations optimized against that readout are evaluated on held-out base images with newly recorded neural responses. The predicted DM is indeed maximized by construction in Eqs. (1)-(2), but the paper does not present that predicted value as the empirical result. The empirical quantities are monkey-measured DM and DOM on images not used in the mapping, and the model overpredicts the measured DM, which directly demonstrates that no fitted constant was tuned to force agreement. The noise corrections, the surrogate mapping-noise simulation with a five-fold efficiency drop, and the report of DOM magnitudes are consistency checks rather than circular steps. The central assumption that model gradients transfer to biological IT circuits is a real correctness risk, but it is tested here by independent held-out physiology data, not assumed into existence. The main caveat is not circularity: experiments 1-3 selected directions by predicted availability (eight most and two least available), so the headline average of 2.7 sigma over 'arbitrary target directions' is a generalization claim that would need availability-stratified reanalysis; this is a sampling/statistical limitation, not a definitional reduction. Self-citations to prior robustified-ANN work are supported by external benchmarks and by the present independent monkey measurements, so they do not constitute load-bearing circular support.

Assumptions & free parameters 4 free parameters · 5 assumptions · 0 invented entities

The paper introduces no new physical entities; its contribution is a control method built on existing ANN tools.

free parameters (4)
  • DOM budget b = 0.1-0.5 sigma (per experiment)
    Chosen by the authors to control the tradeoff between intended DM and allowed orthogonal side effects; the reported precision ratios depend on this choice.
  • DM target t_DM = 10^3
    Arbitrary large target in the loss function (Eq. 2); ensures the DM term is not the binding constraint.
  • DOM penalty coefficient lambda_orth = 10^6
    Arbitrary large penalty for exceeding the DOM budget; effectively makes the budget a hard constraint.
  • PGD step size and iteration count = 0.01, 5000 steps
    Standard optimization hyperparameters; not fitted to neural data but affect the found perturbations.
assumptions (5)
  • domain assumption Robustified ResNet-50 (epsilon_train=2.0, layer 4.0) is an accurate image-computable model of the macaque ventral stream.
    Used as the backbone for the digital twin; the paper cites prior evidence (refs 7-9, 13) but this is an assumption underlying the entire perturbation design. Invoked in 'Modeling an IT population'.
  • domain assumption A linear mapping from model layer 4.0 to IT sites suffices to capture the causal link between pixel perturbations and IT population activity.
    The mapping is fit on natural images; the paper assumes its gradients are predictive for perturbed images. The authors' own simulation shows mapping noise alone causes a five-fold drop in efficiency, so this is load-bearing.
  • domain assumption The identity-covariance canonical space transform makes DM and DOM comparable across sites and populations.
    All target directions and measurements are defined in this transformed space; if the covariance estimate is unstable, the reported precision metrics could be biased. See 'Standardizing measurements' and 'Canonical space transforms'.
  • domain assumption Multi-unit activity recorded with 3-sigma spike threshold and 70-170 ms response windows represents the relevant IT neural code for modulation.
    The central claim about 'neural sites' rests on this operational definition; the paper does not verify that unrecorded neurons are unaffected.
  • domain assumption Site selection using single-repeat reliability >= 0.3 (or 0.4) yields populations for which directional modulation is meaningful.
    This inclusion criterion could bias toward stable sites; the paper states it is consistent with prior work but does not test robustness to the threshold.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Noninvasive precision modulation of high-level neural population activity via natural vision perturbations." pith.science (2026). https://pith.science/paper/KNMQIHDT

@misc{pith2026250605633,
  author       = {Pith},
  title        = {Pith review of: Noninvasive precision modulation of high-level neural population activity via natural vision perturbations},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/KNMQIHDT}},
  note         = {Machine review of arXiv:2506.05633}
}
read the original abstract

Precise control of neural activity -- modulating target neurons deep in the brain while leaving nearby neurons unaffected -- is an outstanding challenge in neuroscience, generally approached using invasive techniques. This study investigates the possibility of precisely and noninvasively modulating neural activity in the high-level primate ventral visual stream via perturbations on one's natural visual feed. When tested on macaque inferior temporal (IT) neural populations, we found quantitative agreement between the model-predicted and biologically realized effect: strong modulation concentrated on targeted neural sites. We extended this to demonstrate accurate injection of experimenter-chosen neural population patterns via subtle perturbations applied on the background of typical natural visual feeds. These results highlight that current machine-executable models of the ventral stream can now design noninvasive, visually-delivered, possibly imperceptible neural interventions at the resolution of individual neurons.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

39 extracted references · 24 canonical work pages

  1. [1]

    E. S. Boyden, F. Zhang, E. Bamberg, G. Nagel, K. Deisseroth, Millisecond-timescale, genetically targeted optical control of neural activity.Nature Neuroscience 2005 8:98(9), 1263–1268 (2005), doi:10.1038/nn1525,https://www.nature.com/articles/nn1525

  2. [2]

    Ditterich, M

    J. Ditterich, M. E. Mazurek, M. N. Shadlen, Microstimulation of visual cortex affects the speed of perceptual decisions.Nature Neuroscience 2003 6:86(8), 891–898 (2003), doi:10.1038/nn1094,https: //www.nature.com/articles/nn1094

  3. [3]

    C. D. Salzman, K. H. Britten, W. T. Newsome, Cortical microstimulation influences perceptual judge- ments of motion direction.Nature 1990 346:6280346(6280), 174–177 (1990), doi:10.1038/346174a0, https://www.nature.com/articles/346174a0

  4. [4]

    O. Yizhar,et al., Neocortical excitation/inhibition balance in information processing and social dys- function.Nature 2011 477:7363477(7363), 171–178 (2011), doi:10.1038/nature10360,https: //www.nature.com/articles/nature10360

  5. [5]

    Chen,et al., Near-infrared deep brain stimulation via upconversion nanoparticle–mediated optoge- netics.Science359(6376), 679–684 (2018),https://www.science.org/doi/10.1126/science

    S. Chen,et al., Near-infrared deep brain stimulation via upconversion nanoparticle–mediated optoge- netics.Science359(6376), 679–684 (2018),https://www.science.org/doi/10.1126/science. aaq1144. 13

  6. [6]

    Jazayeri, A

    M. Jazayeri, A. Afraz, Perspective Navigating the Neural Space in Search of the Neural Code.Neuron93, 1003–1014 (2017), doi:10.1016/j.neuron.2017.02.019,http://dx.doi.org/10.1016/j.neuron. 2017.02.019

  7. [7]

    K. Kar, J. J. DiCarlo, The Quest for an Integrated Set of Neural Mechanisms Underlying Object Recognition in Primates.Annual Review of Vision Science10, 91–121 (2024), doi: 10.1146/ANNUREV-VISION-112823-030616/CITE/REFWORKS,https://www.annualreviews. org/content/journals/10.1146/annurev-vision-112823-030616

  8. [8]

    D. L. K. Yamins, J. J. DiCarlo, Using goal-driven deep learning models to understand sensory cortex. Nature Neuroscience19(3) (2016), doi:10.1038/nn.4244

Show all 39 references
  1. [9]

    N. Kriegeskorte, Deep Neural Networks: A New Framework for Modeling Biological Vi- sion and Brain Information Processing.Annual Review of Vision Science1(1), 417–446 (2015), doi:10.1146/annurev-vision-082114-035447,http://www.annualreviews.org/doi/10. 1146/annurev-vision-082114-035447

  2. [10]

    Bashivan, K

    P. Bashivan, K. Kar, J. J. DiCarlo, Neural population control via deep image synthesis.Science364(6439) (2019),https://www.science.org/doi/10.1126/science.aav9436

  3. [11]

    Guo,et al., Adversarially trained neural representations are already as robust as biological neural representations (2022),https://proceedings.mlr.press/v162/guo22d.html

    C. Guo,et al., Adversarially trained neural representations are already as robust as biological neural representations (2022),https://proceedings.mlr.press/v162/guo22d.html

  4. [12]

    J. J. DiCarlo, D. Zoccolan, N. C. Rust, How Does the Brain Solve Visual Object Recognition?Neu- ron73(3), 415–434 (2012), doi:10.1016/j.neuron.2012.01.010,http://www.ncbi.nlm.nih.gov/ pubmed/22325196

  5. [13]

    Materials and methods are available as supplementary material

  6. [14]

    J. Dapello,et al., Aligning Model and Macaque Inferior Temporal Cortex Representations Improves Model-to-Human Behavioral Alignment and Adversarial Robustness.International Conference on Learning Representations(2023)

  7. [15]

    Schrimpf,et al., Integrative Benchmarking to Advance Neurally Mechanistic Models of Human Intelligence.Neuron108(3), 413–423 (2020), doi:10.1016/J.NEURON.2020.07.040

    M. Schrimpf,et al., Integrative Benchmarking to Advance Neurally Mechanistic Models of Human Intelligence.Neuron108(3), 413–423 (2020), doi:10.1016/J.NEURON.2020.07.040

  8. [16]

    C. R. Ponce,et al., Evolving Images for Visual Neurons Using a Deep Generative Network Reveals Coding Principles and Neuronal Preferences.Cell177(4), 999–1009 (2019),http://www.cell.com/ article/S0092867419303915/fulltext

  9. [17]

    J. J. DiCarlo, J. H. Maunsell, Form representation in monkey inferotemporal cortex is virtually unaltered by free viewing.Nature Neuroscience 2000 3:83(8), 814–821 (2000), doi:10.1038/77722,https: //www.nature.com/articles/nn0800_814

  10. [18]

    A. P. Batista, K. P. Kording, A Deep Dive to Illuminate V4 Neurons.Trends in Neurosciences42, 563–564 (2019), doi:10.1016/j.tins.2019.07.001,https://www.cell.com/action/showFullText? pii=S0166223619301110

  11. [19]

    P. T. Sadtler,et al., Neural constraints on learning.Nature 2014 512:7515512, 423–426 (2014), doi: 10.1038/nature13665,https://www.nature.com/articles/nature13665

  12. [20]

    R. Geirhos,et al., Shortcut learning in deep neural networks.Nature Machine Intelligence 2020 2:11 2(11), 665–673 (2020), doi:10.1038/s42256-020-00257-z,https://www.nature.com/articles/ s42256-020-00257-z. 14

  13. [21]

    S. R. Lehky, R. Kiani, H. Esteky, K. Tanaka, Dimensionality of Object Representations in Mon- key Inferotemporal Cortex.Neural Computation26, 2135–2162 (2014), doi:10.1162/NECO A 00648, https://dx.doi.org/10.1162/NECO_a_00648

  14. [22]

    R. M. Gauthaman, B. M ´enard, M. Bonner, The high-dimensional structure of natural image rep- resentations varies systematically across visual cortex.Journal of Vision24, 796–796 (2024), doi: 10.1167/JOV.24.10.796,https://jov.arvojournals.org/article.aspx?articleid=2800940

  15. [23]

    R. M. Gauthaman, B. M´enard, M. F. Bonner, Universal scale-free representations in human visual cortex. arXiv(2024),https://arxiv.org/pdf/2409.06843

  16. [24]

    Freeman, E

    J. Freeman, E. P. Simoncelli, Metamers of the ventral stream.Nature Neuroscience 2011 14:914, 1195–1201 (2011), doi:10.1038/nn.2889,https://www.nature.com/articles/nn.2889

  17. [25]

    Gaziv, M

    G. Gaziv, M. J. Lee, J. J. DiCarlo, Strong and Precise Modulation of Human Percepts via Robustified ANNs.Advances in Neural Information Processing Systems(2023)

  18. [26]

    M. B. Talbot, G. Kreiman, J. J. DiCarlo, G. Gaziv, L-WISE: Boosting Human Visual Category Learning Through Model-Based Image Selection And Enhancement.arXiv(2024),https://arxiv.org/abs/ 2412.09765v2

  19. [27]

    G. F. Elsayed,et al., Adversarial examples influence human visual perception.Journal of Vision19(10), 190c–190c (2019), doi:10.1167/19.10.190C

  20. [28]

    D. J. Kravitz, K. S. Saleem, C. I. Baker, L. G. Ungerleider, M. Mishkin, The ventral visual pathway: an expanded neural framework for the processing of object quality.Trends in Cognitive Sciences17, 26–49 (2013), doi:10.1016/J.TICS.2012.10.011,https://www.cell.com/action/showF...

  21. [29]

    Stefanacci, D

    L. Stefanacci, D. G. Amaral, Some observations on cortical inputs to the macaque monkey amygdala: An anterograde tracing study.Journal of Comparative Neurology451, 301–323 (2002), doi:10.1002/ CNE.10339,https://onlinelibrary.wiley.com/doi/full/10.1002/cne.10339

  22. [30]

    Blackrock Neurotech,https://blackrockneurotech.com/

  23. [31]

    MWorks version v0.13,https://mworks.github.io/

  24. [32]

    C. P. Hung, Fast Readout of Object Identity from Macaque Inferior Temporal Cortex.Science310(5749), 863–866 (2005), doi:10.1126/science.1117593,http://www.sciencemag.org/cgi/doi/10.1126/ science.1117593

  25. [33]

    K. Kar, J. J. DiCarlo, Fast Recurrent Processing via Ventrolateral Prefrontal Cortex Is Needed by the Primate Ventral Stream for Robust Core Visual Object Recognition.Neuron109(1), 164–176 (2021), doi:10.1016/J.NEURON.2020.09.035

  26. [34]

    N. J. Majaj, H. Hong, E. A. Solomon, J. J. DiCarlo, Simple Learned Weighted Sums of Inferior Temporal Neuronal Firing Rates Accurately Predict Human Core Object Recognition Performance.Journal of Neuroscience35(39), 13402–13418 (2015), doi:10.1523/JNEUROSCI.5181-14.2015,https:...

  27. [35]

    Deng,et al., ImageNet: A large-scale hierarchical image database, in2009 IEEE Conference on Com- puter Vision and Pattern Recognition(IEEE) (2009), pp

    J. Deng,et al., ImageNet: A large-scale hierarchical image database, in2009 IEEE Conference on Com- puter Vision and Pattern Recognition(IEEE) (2009), pp. 248–255, doi:10.1109/CVPR.2009.5206848, http://ieeexplore.ieee.org/document/5206848/. 15

  28. [36]

    ILSVRC, doi:10.1007/s11263-015-0816-y,https://www.image-net.org/challenges/LSVRC/

  29. [37]

    Gaziv, M

    G. Gaziv, M. J. Lee, J. J. DiCarlo, Robustified ANNs Reveal Wormholes Between Human Category Percepts.arXiv(2023),https://arxiv.org/abs/2308.06887v1

  30. [38]

    Ma ¸dry, A

    A. Ma ¸dry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks (2018),https://github.com/MadryLab/cifar10_challenge

  31. [39]

    rose-colored glasses

    Adobe Photoshop v25.7.0. Acknowledgments We thank C. Guo and M. Lee for insightful discussions, and C. Shay for administrative support. Funding:This work was partially funded by the Office of Naval Research (N00014-20-1-2589, JJD), and the Simons Foundation (NC-GB-CULM-0000298...

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.