Comparing Detection Schemes for Adversarial Images against Deep Learning Models for Cancer Imaging
Marina Z. Joel, Arman Avesta, Daniel X. Yang, Jian‐Ge Zhou, Antonio Omuro, Roy S. Herbst, Harlan M. Krumholz, Sanjay Aneja
Johns Hopkins University Johns Hopkins Medicine Yale University Jackson State University
内容与影响
Deep learning (DL) models have demonstrated state-of-the-art performance in the classification of diagnostic imaging in oncology. However, DL models for medical images can be compromised by adversarial images, where pixel values of input images are manipulated to deceive the DL model. To address this limitation, our study investigates the detectability of adversarial images in oncology using multiple detection schemes. Experiments were conducted on thoracic computed tomography (CT) scans, mammography, and brain magnetic resonance imaging (MRI). For each dataset we trained a convolutional neural network to classify the presence or absence of malignancy. We trained five DL and machine learning (ML)-based detection models and tested their performance in detecting adversarial images. Adversarial images generated using projected gradient descent (PGD) with a perturbation size of 0.004 were detected by the ResNet detection model with an accuracy of 100% for CT, 100% for mammogram, and 90.0% for MRI. Overall, adversarial images were detected with high accuracy in settings where adversarial perturbation was above set thresholds. Adversarial detection should be considered alongside adversarial training as a defense technique to protect DL models for cancer imaging classification from the threat of adversarial images.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
回答优先基于摘要、文献信息与可获取全文;依据不足时会明确说明。
学术脉络
学科主题
生物医学Artificial Intelligence in Healthcare and Education
Adversarial Robustness in Machine Learning · Advanced X-ray and CT Imaging
参考文献 34
此处列出前 3 条
施引文献 10
按被引量排序,此处列出前 3 条