Natural Language Descriptions of Deep Visual Features
Evan Hernandez, Sarah Schwettmann, David Bau, Teona Bagashvili, Antonio Torralba, Jacob Andreas
Introduction
A surprising amount can be learned about the behavior of a deep network by understanding the individual neurons that make it up. Previous studies aimed at visualizing or automatically categorizing neurons have identified a range of interpretable functions across models and application domains: low-level convolutional units in image classifiers implement color detectors and Gabor filters (Erhan et al., 2009), while some later units activate for specific parts and object categories (Zeiler & Fergus, 2014; Bau et al., 2017). Single neurons have also been found to encode sentiment in language data (Radford et al., 2017) and biological function in computational chemistry (Preuer et al., 2019). Given a new model trained to perform a new task, can we automatically catalog these behaviors?
Techniques for characterizing the behavior of individual neurons are still quite limited. Approaches based on visualization (Zeiler & Fergus, 2014; Girshick et al., 2014; Karpathy et al., 2015; Mahendran & Vedaldi, 2015; Olah et al., 2017) leave much of the work of interpretation up to human users, and cannot be used for large-scale analysis. Existing automated labeling techniques (Bau et al., 2017; 2019; Mu & Andreas, 2020) require researchers to pre-define a fixed space of candidate neuron labels; they label only a subset of neurons in a given network and cannot be used to surface novel or unexpected behaviors.
This paper develops an alternative paradigm for labeling neurons with expressive, compositional, and open-ended annotations in the form of natural language descriptions. We focus on the visual domain: building on past work on information-theoretic approaches to model interpretability, we formulate neuron labeling as a problem of finding informative descriptions of a neuron’s pattern of activation on input images. We describe a procedure (called milan, for mutual-information-guided linguistic annotation of neurons) that labels individual neurons with fine-grained natural language descriptions by searching for descriptions that maximize pointwise mutual information with the image regions in which neurons are active. To do so, we first collect a new dataset of fine-grained image annotations (milannotations, Figure 1c), then use these to construct learned approximations to the distributions over image regions (Figure 1b) and descriptions. In some cases, milan surfaces neuron descriptions that more specific than the underlying training data (Figure 1d).
milan is largely model-agnostic and can surface descriptions for different classes of neurons, ranging from convolutional units in CNNs to fully connected units in vision transformers, even when the target network is trained on data that differs systematically from milannotations’ images. These descriptions can in turn serve a diverse set of practical goals in model interpretability and dataset design. Our experiments highlight three: using milan-generated descriptions to (1) analyze the role and importance of different neuron classes in convolutional image classifiers, (2) audit models for demographically sensitive feature by comparing their features when trained on anonymized (blurred) and non-anonymized datasets, and (3) identify and mitigate the effects of spurious correlations with text features, improving classifier performance on adversarially distributed test sets. Taken together, these results show that fine-grained, automatic annotation of deep network models is both possible and practical: rich descriptions produced by automated annotation procedures can surface meaningful and actionable information about model behavior.
Related Work
milan builds on a long line of recent approaches aimed at explaining the behavior of deep networks by characterizing the function of individual neurons, either by visualizing the inputs they select for (Zeiler & Fergus, 2014; Girshick et al., 2014; Karpathy et al., 2015; Mahendran & Vedaldi, 2015; Olah et al., 2017) or by automatically categorizing them according to the concepts they recognize (Bau et al., 2017; 2018; Mu & Andreas, 2020; Morcos et al., 2018; Dalvi et al., 2019). Past approaches to automatic neuron labeling require fixed, pre-defined label sets; in computer vision, this has limited exploration to pre-selected object classes, parts, materials, and simple logical combinations of these concepts. While manual inspection of neurons has revealed that a wider range of features play an important role in visual recognition (e.g. orientation, illumination, and spatial relations; Cammarata et al. 2021) milan is the first automated approach that can identify such features at scale. Discrete categorization is also possible for directions in representation space (Kim et al., 2018; Andreas et al., 2017; Schwettmann et al., 2021) and for clusters of images induced by visual representations (Laina et al., 2020); in the latter, an off-the-shelf image captioning model is used to obtain language descriptions of the unifying visual concept for the cluster, although the descriptions miss low-level visual commonalities. As milan requires only a primitive procedure for generating model inputs maximally associated with the feature or direction of interest, future work might extend it to these settings as well.
Natural language explanations of decisions
Previous work aimed at explaining computer vision classifiers using natural language has focused on generating explanations for individual classification decisions (e.g., Hendricks et al., 2016; Park et al., 2018; Hendricks et al., 2018; Zellers et al., 2019). Outside of computer vision, several recent papers have proposed procedures for generating natural language explanations of decisions in text classification models (Zaidan & Eisner, 2008; Camburu et al., 2018; Rajani et al., 2019; Narang et al., 2020) and of representations in more general sequence modeling problems (Andreas & Klein, 2017). These approaches require task-specific datasets and often specialized training procedures, and do not assist with interpretability at the model level. To the best of our knowledge, milan is the first approach for generating compositional natural language descriptions for interpretability at the level of individual features rather than input-conditional decisions or representations. More fundamentally, milan can do so independently of the model being described, making it (as shown in Section 4) modular, portable, and to a limited extent task-agnostic.
Approach
Consider the neuron depicted in Figure 1b, located in a convlutional network trained to classify scenes (Zhou et al., 2017). When the images in Figure 1 are provided as input to the network, the neuron activates in patches of grass near animals, but not in grass without animals nearby. How might we automate the process of automatically generating such a description?
While the image regions depicted in Fig. 1b do not completely characterize the neuron’s function in the broader network, past work has found that actionable information can be gleaned from such regions alone. Bau et al. (2020; 2019) use them to identify neurons that can trigger class predictions or generative synthesis of specific objects; Andreas & Klein (2017) use them to predict sequence outputs on novel inputs; Olah et al. (2018) and Mu & Andreas (2020) use them to identify adversarial vulnerabilities. Thus, building on this past work, our approach to neuron labeling also begins by representing each neuron via the set of input regions on which its activity exceeds a fixed threshold.
Let be a neural network, and let denote the activation value of the th neuron in given an input .In this paper, we will be primarily concerned with neurons in convolutional layers; for each neuron, we will thus take the input space to be the space of all image patches equal in size to the neuron’s receptive field. Then, an exemplar representation of the neuron is given by:
for some threshold parameter (discussed in more detail below).
Exemplars and descriptions
Given this explicit representation of ’s behavior, it remains to construct a description of the neuron. Past work (Bau et al., 2017; Andreas et al., 2017) begins with a fixed inventory of candidate descriptions (e.g. object categories), defines an exemplar set for each such category (e.g. via the output of a semantic segmentation procedure) then labels neurons by optimizing for some measure of set distance (e.g. Jaccard, 1912).
In this work, we instead adopt a probabilistic approach to neuron labeling. In computer vision applications, each is a set of image patches. Humans are adept at describing such patches (Rashtchian et al., 2010) and one straightforward possibility might be to directly optimize . In practice, however, the distribution of human descriptions given images may not be well-aligned with the needs of model users. Fig. 2 includes examples of human-generated descriptions for exemplar sets. Many of them (e.g. text for AlexNet conv3-252) are accurate, but generic; in reality, the neuron responds specifically to text on screens. The generated description of a neuron should capture the specificity of its function—especially relative to other neurons in the same model.
We thus adopt an information-theoretic criterion for selecting descriptions: our final neuron description procedure optimizes pointwise mutual information between descriptions and exemplar sets:
The max-mutual-information description of the neuron is given by:
To turn Eq. 2 into a practical procedure for annotating neurons, three additional steps are required: constructing a tractable approximation to the exemplar set (Section 3.1), using human-generated image descriptions to model and (Section 3.2 and Section 3.3), and finding a high-quality description in the infinite space of natural language strings (Section 3.4).
1 Approximating the exemplar set
As written, the exemplar set in Equation 1 captures a neuron’s behavior on all image patches. This set is large (limited only by the precision used to represent individual pixel values), so we follow past work (Bau et al., 2017) by restricting each to the set of images that cause the greatest activation in the neuron . For convolutional neurons in image processing tasks, sets ultimately comprise images with activation masks indicating the regions of those images in which fired (Fig. 1a; see Bau et al. 2017 for details). Throughout this paper, we use exemplar sets with images and choose equal to the 0.99 percentile of activations for the neuron .
2 Modeling p(d∣E)𝑝conditional𝑑𝐸p(d\mid E) and p(d)𝑝𝑑p(d)
3 Collecting human annotations
As and are both estimated using learned models, they require training data. In particular, modeling requires a dataset of captions that describe regions from multiple different images, such as the ones shown in Fig. 1. These descriptions must describe not only objects and actions, but all other details that individual neurons select for. Existing image captioning datasets, like MSCOCO (Lin et al., 2014) and Conceptual Captions (Sharma et al., 2018), only focus on scene-level details about a single image and do not provide suitable annotations for this task. We therefore collect a novel dataset of captions for image regions to train the models underlying milan.
First, we must obtain a set of image regions to annotate. To ensure that these regions have a similar distribution to the target neurons themselves, we derive them directly from the exemplar sets of neurons in a set of seed models. We obtain the exemplar sets for a subset of the units in each seed model in Table 1 using the method from Section 3.1. We then present each set to a human annotator and ask them to describe what is common to the image regions.
Table 1 summarizes the dataset, which we call milannotations. In total, we construct exemplar sets using neurons from seven vision models, totaling 20k neurons. These models include two architectures for supervised image classification, AlexNet (Krizhevsky et al., 2012) and ResNet152 (He et al., 2015); one architecture for image generation, BigGAN (Brock et al., 2018); and one for unsupervised representation learning trained with a “Bootsrap Your Own Latent” (BYOL) objective (Chen & He, 2020; Grill et al., 2020), DINO (Caron et al., 2021). These models cover two datasets, specifically ImageNet (Deng et al., 2009) and Places365 (Zhou et al., 2017), as well as two completely different families of models, CNNs and Vision Transformers (ViT) (Dosovitskiy et al., 2021). Each exemplar set is shown to three distinct human participants, resulting 60k total annotations. Examples are provided in Appendix A (Fig. 10). We recruit participants from Amazon Mechanical Turk. This data collection effort was approved by MIT’s Committee on the Use of Humans as Experimental Subjects. To control for quality, workers were required to have a HIT acceptance rate of at least 95%, have at least 100 approved HITs, and pass a short qualification test. Full details about our data collection process and the collected data can be found in Appendix A.
4 Searching in the space of descriptions
Next, search is restricted to a set of captions that are high probability under , which are reranked according to Eq. 3. Specifically, we run beam search on , and use the full beam after the final search step as a set of candidate descriptions. For all experiments, we set and beam size to 50.
Does milan generalize?
Because it is trained on a set of human-annotated exemplar sets obtained from a set of seed networks, milan is useful as an automated procedure only if it generalizes and correctly describes neurons in trained models with new architectures, new datasets, and new training objectives. Thus, before describing applications of milan to specific interpretability problems, we perform cross-
validation experiments within the milannotations data to validate that milan can reliably label new neurons. We additionally verify that milan provides benefits over other neuron annotation techniques by comparing its descriptions to three baselines: NetDissect (Bau et al., 2017), which assigns a single concept label to each neuron by comparing the neuron’s exemplars to semantic segmentations of the same images; Compositional
In each experiment, we train milan on a subset of milannotations and evaluate its performance on a held-out subset. To compare milan to the baselines, we train on all data except a single held-out network; we obtain the baseline labels by running the publicly available code with the default settings on the held-out network. To test generalization within a network, we train on 90% of neurons from each network and test on the remaining 10%. To test generalization across architectures, we train on all AlexNet (ResNet) neurons and test on all ResNet (AlexNet) neurons; we also train on all CNN neurons and test on ViT neurons. To test generalization across datasets, we train on all neurons from models trained on ImageNet (Places) and test on neurons from models for the other datasets. To test generalization across tasks, we train on all classifier neurons (GAN neurons) and test on all GAN neurons (classifier neurons). We measure performance via BERTScore (Zhang et al., 2020) relative to the human annotations. Hyperparameters for each of these experiments are in Appendix C.
Results
Table 3 shows that milan exhibits different degrees of generalization across models, with generalization to new GAN neurons in the same network easiest and GAN-to-classifier generalization hardest. milan can generalize to novel architectures. It correctly labels ViT neurons (in fully connected layers) as often as it correctly labels other convolutional units (e.g., in AlexNet). We observe that transferability across tasks is asymmetric: agreement scores are higher when transferring from classifier neurons to GAN neurons than the reverse. Finally, Figure 3 presents some of milan’s failure cases: when faced with new visual concepts, milan sometimes mislabels the concept (e.g., by calling brass instruments noodle dishes), prefers a vague description (e.g., similar color patterns), or ignores the highlighted regions and describes the context instead.
We emphasize that this section is primarily intended as a sanity check of the learned models underlying milan, and not as direct evidence of its usefulness or reliability as a tool for interpretability. We
follow Vaughan & Wallach (2020) in arguing that the final test of any such tool must be its ability to produce actionable insights for human users, as in the three applications described below.
Analyzing Feature Importance
The previous section shows that milan can generalize to new architectures, datasets, and tasks. The remainder of this paper focuses on applications that use generated labels to understand how neurons influence model behavior. As a first example: descriptions in Figure 2 reveal that neurons have different degrees of specificity. Some neurons detect objects with spatial constraints (the area on top of the line), while others fire for low-level but highly specific perceptual qualities (long, thin objects). Still others detect perceptually similar but fundamentally different objects (dog faces and cupcakes). How important are these different classes of neurons to model behavior?
We use milan trained on all convolutional units in milannotations to annotate every neuron in ResNet18-ImageNet. We then score each neuron according to one of seven criteria that capture different syntactic or structural properties of the caption. Four syntactic criteria each count the number of times that a specific part of speech appears in a caption: nouns, verbs, prepositions, and adjectives. Three structural criteria measure properties of the entire caption: its length, the depth of its parse tree (a rough measure of its compositional complexity, obtained from the spaCy parser of Honnibal et al. 2020), and its maximum word difference (a measure of the semantic coherence of the description, measured as the maximum Euclidean distance between any two caption words, again obtained via spaCy). Finally, neurons are incrementally ablated in order of their score. The network is tested on the ImageNet validation set and its accuracy recorded. This procedure is then repeated, deleting 2% of neurons at each step. We also include five trials in which neurons are ordered randomly. Further details and examples of ablated neurons are provided in Appendix D.
Results
Figure 4 plots accuracy on the ImageNet validation set as a function of the number of ablated neurons. Linguistic features of neuron descriptions highlight several important differences between neurons. First, neurons captioned with many adjectives or prepositions (that is, neurons that capture attributes and relational features) are relatively important to model behavior. Ablating these neurons causes a rapid decline in performance compared to ablating random neurons or nouns. Second, neurons that detect dissimilar concepts appear to be less important. When the caption contains highly dissimilar words (max word diff.), ablation hurts performance substantially less than ablating random neurons. Such neurons sometimes detect non-semantic compositions of concepts like the dog faces and cupcakes neuron shown in Fig. 2; Mu & Andreas (2020) find that these units contribute to non-robust model behavior. We reproduce their robustness experiments using these neurons in Section 5 (Figure 14) and reach similar conclusions. Finally, Figure 4 highlights that neurons satisfying each criterion are not evenly distributed across layers—for example, middle layers contain the largest fraction of relation-selective neurons measured via prepositions.
Auditing Anonymized Models
One recent line of work in computer vision aims to construct privacy-aware datasets, e.g. by detecting and blurring all faces to avoid leakage of information about specific individuals into trained models (Yang et al., 2021). But to what extent does this form of anonymization actually reduce
models’ reliance on images of humans? We wish to understand if models trained on blurred data still construct features that can human faces, or even specific categories of faces. A core function of tools for interpretable machine learning is to enable auditing of trained models for such behavior; here, we apply milan to investigate the effect of blurring-based dataset privacy.
We use milan to caption a subset of convolutional units in 12 different models pretrained for image classification on the blurred ImageNet images (blurred models). These models are distributed by the original authors of the blurred ImageNet dataset (Yang et al., 2021). We caption the same units in models pretrained on regular ImageNet (unblurred models) obtained from torchvision (Paszke et al., 2019). We then manually inspect all neurons in the blurred and unblurred models for which milan descriptions contain the words face, head, nose, eyes, and mouth (using exemplar sets containing only unblurred images).
Results
Across models trained on ordinary ImageNet, milan identified 213 neurons selective for human faces. Across models trained on blurred ImageNet, milan identified 142 neurons selective for human faces. milan can distinguish between models trained on blurred and unblurred data (Fig. 5). However, it also reveals that models trained on blurred data acquire neurons selective for unblurred faces. Indeed, it is possible to use milan’s labels to extract these face-selective neurons directly. Doing so reveals that several of them are not simply face detectors, but appear to selectively identify female faces (Fig. 6b) and Asian faces (Fig. 6c). Blurring does not prevent models from extracting highly specific features for these attributes. Our results in this section highlight the use of milan for both quantitative and qualitative, human-in-the loop auditing of model behavior.
Editing Spurious Features
Spurious correlations between features and labels are a persistent problem in machine learning applications, especially in the presence of mismatches between training and testing data (Storkey, 2009). In object recognition, one frequent example is correlation between backgrounds and objects (e.g. cows are more likely to appear with green grass in the background, while fish are more likely to appear with a blue background; Xiao et al. 2020). In a more recent example, models trained on joint text and image data are subject to “text-based adversarial attacks”, in which e.g. an apple with the word iPod written on it is classified as an iPod (Goh et al., 2021). Our final experiment shows that milan can be used to reduce models’ sensitivity to these spurious features.
We create a controlled dataset imitating Goh et al. (2021)’s spurious text features. The dataset consists of 10 ImageNet classes. In the training split, there are 1000 images per class; 500 are annotated with (correct) text labels in the top-left corner. The test set contains 100 images per class (from the ImageNet validation set); in all these images, a random (usually incorrect) text label is included. We train and evaluate a fresh ResNet18 model on this dataset, holding out 10% of the training data as a validation dataset for early stopping. Training details can be found in Appendix E.
Method
We use milan to obtain descriptions of every residual neuron in the model as well as the first convolutional layer. We identify all neurons whose description contains text, word, or letter. To identify spurious neurons, we first assign each text neuron an independent importance score by removing it from the network and measuring the resulting drop in validation accuracy (with non-adversarial images). We then sort neurons by importance score (with the least important first), and successively ablate them from the model.
Results
The result of this procedure on adversarial test accuracy is shown in Fig. 8. Training on the spurious data substantially reduces ResNet18’s performance on the adversarial test set: the model achieves 58.8% accuracy, as opposed to 69.9% when tested on non-spurious data. milan identifies 300 text-related convolutional units (out of 1024 examined) in the model, confirming that the model has indeed devoted substantial capacity to identifying text labels in the image. Figure 7c shows an example neurons specifically selective for airline and truck text. By deleting only 13 such neurons, test accuracy is improved by 4.9% (a 12% reduction in overall error rate).Stopping criteria are discussed more in Appendix E; if no adversarial data is used to determine the number of neurons to prune, an improvement of 3.1% is still achievable. This increase cannot be explained by the sorting procedure described above: if instead we sort all neurons according to validation accuracy (orange line), accuracy improves by less than 1%. Thus, while this experiment does not completely eliminate the model’s reliance on text features, it shows that milan’s predictions enable direct editing of networks to partially mitigate sensitivity to spurious feature correlations.
Conclusions
We have presented milan, an approach for automatically labeling neurons with natural language descriptions of their behavior. milan selects these descriptions by maximizing pointwise mutual information with image regions in which each neuron is active. These mutual information estimates are in turn produced by a pair of learned models trained on milannotations, a dataset of fine-grained image annotations released with this paper. Descriptions generated by milan surface diverse aspects of model behavior, and can serve as a foundation for numerous analysis, auditing, and editing techniques workflows for users of deep network models.
Impact statement
In contrast to most past work on neuron labeling, milan generates neuron labels using another black-box learned model trained on human annotations of visual concepts. With this increase in expressive power come a number of potential limitations: exemplar-based explanations have known shortcomings (Bolukbasi et al., 2021), human annotations of exemplar sets may be noisy, and the captioning model may itself behave in unexpected ways far outside the training domain. The milannotations dataset was collected with annotator tests to address potential data quality issues, and our evaluation in Section 4 characterizes prediction quality on new networks; we nevertheless emphasize that these descriptions are partial and potentially noisy characterizations of neuron function via their behavior on a fixed-sized set of representative inputs. milan complements, rather than replaces, both formal verification (Dathathri et al., 2020) and careful review of predictions and datasets by expert humans (Gebru et al., 2018; Mitchell et al., 2019).
Acknowledgments
We thank Ekin Akyürek and Tianxing He for helpful feedback on early drafts of the paper. We also thank IBM for the donation of the Satori supercomputer that enabled training BigGAN on MIT Places. This work was partially supported by the MIT-IBM Watson AI lab, the SystemsThatLearn initiative at MIT, a Sony Faculty Innovation Award, DARPA SAIL-ON HR0011-20-C-0022, and a hardware gift from NVIDIA under the NVAIL grant program.
References
Appendix A milannotations
We recruited annotators from Amazon Mechanical Turk to describe one neuron at a time given its top-activating images. A screenshot of the template is shown in Figure 9b. Participants were given the instructions:
Instructions: In one sentence, summarize everything shown inside the highlighted regions in the images. They might all show the same thing, or they might show several different things.
In your answer, DO NOT mention that you are describing highlighted regions in images.
Workers were given up to an hour to complete each annotation, but early trials revealed they required about 30 seconds per HIT. We paid workers 9.60 per hour exceeds the United States federal minimum wage.
To control for quality, we required workers to pass a short qualification test in which they had to choose the most descriptive caption for two manually chosen neurons from VGG-16 (Simonyan & Zisserman, 2015) trained on ImageNet (not included as part of milannotations). A screenshot of this test is shown in Figure 9a.
Table 4 shows the inter-annotator agreement of neuron annotations for each model, and Table 5 shows some corpus statistics broken down by model and layer. Layers closest to the image (early layers in CNNs and later layers in GANs) are generally described with more adjectives than other layers, while annotations for layers farther from the image include more nouns, perhaps highlighting the low-level perceptual role of the former and the scene- and object-centric behavior of the latter. Layers farther from the image tend to have longer descriptions (e.g. in BigGAN-ImageNet, AlexNet-ImageNet), but this trend is not consistent across all models (e.g. in models trained on Places365, the middle layers have the longest average caption length).
Appendix B milan implementation details
We build on the Show, Attend, and Tell (SAT) model for describing images (Xu et al., 2015). SAT is designed for describing the high-level content of a single images, so we must make several modifications to support our use case, where our goal is to describe sets of regions in images.
In the original SAT architecture, a single input image is first converted to visual features by passing it through an encoder network , typically an image classifier pretrained on a large dataset. The output of the last convolutional layer is extracted as a matrix of visual features:
These visual features are passed to a decoder LSTM whose hidden state is initialized as a function of the mean of the visual features . At each time step, the decoder attends over the features using an additive attention mechanism (Bahdanau et al., 2015), then consumes the attenuated visual features and previous token as input to predict the next token.
The SAT architecture makes few assumptions about the structure of the visual features. We will take advantage of this generality and modify how is constructed to support our task, leaving the decoder architecture intact.
Now, instead of a single image , the model inputs are the top-activating images for a neuron as well as a mask for each image that highlights the regions of greatest activation. Our task is to describe what the neuron is detecting, based strictly on the highlighted regions of the . In support of this, the visual features must (1) include information about all images, (2) encode multiple resolutions of the images to capture both low-level perceptual and high-level scene details about the image, and (3) pay most (but not exclusive) attention to the regions of greatest activation in the image.
The features in SAT correspond to different spatial localities of a single image. In our architecture, each feature corresponds to one input image .
Encoding multiple resolutions
Highlighting regions of greatest activation
Throughout our experiments, is a ResNet101 pretrained for image classification on ImageNet, provided by PyTorch Paszke et al. (2019). We extract visual features from the first convolutional layer and all four residual layers. We do not fine tune any parameters in the encoder. The decoder is a single LSTM cell with an input embedding size of 128 and a hidden size of 512. The attention mechanism linearly maps the current hidden state and all visual feature vectors to size 512 vectors before computing attention weights. We always decode for a maximum of 15 steps. The rest of the decoder is exactly the same as in Xu et al. (2015).
The model is trained to minimize cross entropy on the training set using the AdamW optimizer Loshchilov & Hutter (2019) with a learning rate of 1e-3 and minibatches of size 64. We include the double stochasticity regularization term used by Xu et al. (2015) with . We also apply dropout () to the hidden state before predicting the next word. Across configurations, 10% of the training data is held out and used as a validation set, and training stops when the model’s BLEU score (Papineni et al., 2002) does not improve on this set for 4 epochs, up to a maximum of 100 epochs.
B.2 Implementing p(d)𝑝𝑑p(d)
We implement using a two-layer LSTM language model (Hochreiter & Schmidhuber, 1997). We use an input embedding size of 128 with a hidden state size and cell size of 512. We apply dropout to non-recurrent connections during training and hold out 10% of the training dataset as a validation set and following the same early stopping procedure as in Section B.1, except we stop on validation loss instead of BLEU.
Appendix C Generalization experiment details
In each experiment, milan is trained with the hyperparameters described in Appendix B and Section 3.4, with the sole exception being the within-network splits—for these, we increase the early stopping criterion to require 10 epochs of no improvement to account for the training instability caused by the small training set size.
To obtain NetDissect labels, we obtain image exemplars with the same settings as we do for milan, and we obtain segmentations using the full segmentation vocabulary minus the textures.
To obtain Compositional Explanations labels, we search for up to length 3 formulas (comprised of not, and, and or operators) with a beam size of 5 and no length penalty. Image region exemplars and corresponding segmentations come from the ADE20k dataset (Zhou et al., 2019).
Finally, Table 6 shows statistics for milan descriptions generated on the held out sets from each generalization experiment. Compared to human annotators (Table 5), milan descriptions are on average shorter (2.7 vs. 4.5 tokens), use fewer unique words (1k vs. 4.6k), and contain adjectives twice as often (9.4% vs. 19.8%). Figure 12 contains additional examples, chosen at random.
Appendix D Analysis experiment details
We obtain the ResNet18 model pretrained on ImageNet from torchvision (Paszke et al., 2019). We obtain neuron descriptions for the same layers that we annotate in ResNet152 (Section 3.3) using the milan hyperparameters described in Section 3.2 and Section 3.4. We obtain part of speech tags, parse trees, and word vectors for each description from spaCy (Honnibal et al., 2020).
Figure 13 shows examples of neurons that scored high under each criterion (and consequently were among the first ablated in Fig. 5). Note that these examples include some failure cases of milan: for example, in the # verbs example, milan incorrectly categorizes all brass instruments as flutes; and in the # adjectives example, the description is disfluent. Nevertheless, these examples confirm our intuitions about the kinds of neurons selected for by each scoring criterion, as described in Section 5.
We hypothesized in Section 5 that neurons scoring high on the max-word-diff criterion correspond to non-robust behavior by the model. Figure 14 provides some evidence for this hypothesis: we construct cut-and-paste adversarial inputs in the style of Mu & Andreas (2020). Specifically, we look at the example max-word-diff neuron shown in Figure 13, crudely copy and paste one of the objects mentioned in its description (e.g., a vehicle-related object like a half track), and show that this can cause the model to predict one of the other concepts in the description (e.g., an animal-related class like amphibian).
Appendix E Editing experiment details
We train a randomly initialized ResNet18 on the spurious training dataset for a maximum of 100 epochs with a learning rate of 1e-4 and a minibatch size of 128. We annotate the same convolutional and residual units we did for ResNet152 in Section 3.3. We stop training when validation loss does not improve for 4 epochs.
How many neurons should we remove?
In practice, we cannot incrementally test our model on an adversarial set. So how do we decide on the number of neurons to zero? One option is to look solely at validation accuracy. Figure 15 recreates Figure 8 with accuracy on the held out validation set (which is distributed like the training dataset) instead of accuracy on the adversarial test set. The accuracy starts peaks and starts decreasing earlier than in Fig. 8, but if we were to choose the number to be the largest before validation accuracy permanently decreases, we would choose 8 neurons, which would still result in a 3.1% increase in adversarial accuracy.