Measuring Robustness and Efficiency in a Connectome-Constrained Fly Visual System Model on a Collision-Detection Task
Abstract
Biological visual systems compute reliably under tight metabolic and wiring constraints despite noisy inputs and stochastic circuit components. Artificial vision systems tend to invert both properties: They consume vastly more energy and can be sensitive to adversarial perturbations. Whether artificial networks with structural properties of real brain wiring are more robust at lower computational cost is unclear. We address this with FlyNet (Lappalainen et al. 2024), a task-optimized, continuous-time neural network model of the fly visual system constrained by its synaptic connectome. We benchmark it against CNN, RAFT (Teed and Deng, 2020), and a sparse continuous-time recurrent neural network without connectome constraints (CTRNN) on a looming-based collision-detection task within a differentiable 3D rendering pipeline. We find that FlyNet is more robust than CNN controls to flicker, unstructured noise, and motion jitter. Compared with RAFT controls, FlyNet is more robust to flicker and motion jitter but less robust to all gradient-based attacks. Yet, FlyNet uses up to five orders of magnitude fewer FLOPs than RAFT, achieving higher robustness on common video corruptions at far lower cost. FlyNet is less robust than CTRNN across all tested perturbations, suggesting that FlyNet's connectome constraints contribute to cost, not robustness. To probe FlyNet's failure modes, we use counterfactual restoration: textures equally far from training as adversarial textures that recover correct classification also recover position and velocity representations, ruling out unfamiliar textures as the cause of failure. Classical reverse-phi illusions degrade the same downstream position and velocity readouts, suggesting that both perturbations may exploit similar computational vulnerabilities. Together, these results show that FlyNet is robust for its computational cost on an ecologically important task, and indicate that different architectures specialized on the same task have specific robustness profiles across perturbation types. Our differentiable pipeline enables computational tests of this hypothesis and generates targeted adversarial stimuli for in vivo experiments.