Understanding Adversarial Attacks on Deep Learning Based Medical Image Analysis Systems
arXiv:1907.10456 · doi:10.1016/j.patcog.2020.107332
Abstract
Deep neural networks (DNNs) have become popular for medical image analysis tasks like cancer diagnosis and lesion detection. However, a recent study demonstrates that medical deep learning systems can be compromised by carefully-engineered adversarial examples/attacks with small imperceptible perturbations. This raises safety concerns about the deployment of these systems in clinical settings. In this paper, we provide a deeper understanding of adversarial examples in the context of medical images. We find that medical DNN models can be more vulnerable to adversarial attacks compared to models for natural images, according to two different viewpoints. Surprisingly, we also find that medical adversarial attacks can be easily detected, i.e., simple detectors can achieve over 98% detection AUC against state-of-the-art attacks, due to fundamental feature differences compared to normal examples. We believe these findings may be a useful basis to approach the design of more explainable and secure medical deep learning systems.
15 pages, 11 figures, to appear in Pattern Recognition
References in corpus (10)
- Explaining and Harnessing Adversarial Examples
- CheXNet: Radiologist-Level Pneumonia Detection on Chest X-Rays with Deep Learning
- The Space of Transferable Adversarial Examples
- Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients
- On Detecting Adversarial Perturbations
- On the Convergence and Robustness of Adversarial Training
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNets
- DeepOrgan: Multi-level Deep Convolutional Networks for Automated Pancreas Segmentation
- Interpreting and Improving Adversarial Robustness of Deep Neural Networks with Neuron Sensitivity
- PDA: Progressive Data Augmentation for General Robustness of Deep Neural Networks
Cited by in corpus (52)
- Deep neural network models for computational histopathology: A survey
- Explainable Artificial Intelligence: A Survey of Needs, Techniques, Applications, and Future Direction
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks
- Adversarial Attack Vulnerability of Medical Image Analysis Systems: Unexplored Factors
- Review: Deep Learning in Electron Microscopy
- Explainable, Domain-Adaptive, and Federated Artificial Intelligence in Medicine
- Explainable Diabetic Retinopathy Detection and Retinal Image Generation
- Towards Understanding and Boosting Adversarial Transferability from a Distribution Perspective
- Towards Evaluating the Robustness of Deep Diagnostic Models by Adversarial Attack
- Survey on Adversarial Attack and Defense for Medical Image Analysis: Methods and Challenges
- Unlearnable Examples: Making Personal Data Unexploitable
- Explainable Artificial Intelligence (XAI): An Engineering Perspective
- Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks
- On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome Them
- Exploring Architectural Ingredients of Adversarially Robust Deep Neural Networks
- Adversarial Attacks and Defenses in Physiological Computing: A Systematic Review
- When and How to Fool Explainable Models (and Humans) with Adversarial Examples
- Improving deep learning with prior knowledge and cognitive models: A survey on enhancing explainability, adversarial robustness and zero-shot learning
- TMS-Net: A Segmentation Network Coupled With A Run-time Quality Control Method For Robust Cardiac Image Segmentation
- Adversarial Camouflage: Hiding Physical-World Attacks with Natural Styles
- Clean-Label Backdoor Attacks on Video Recognition Models
- Stabilized Medical Image Attacks
- VT-ADL: A Vision Transformer Network for Image Anomaly Detection and Localization
- UnbiasedNets: A Dataset Diversification Framework for Robustness Bias Alleviation in Neural Networks
- On Adversarial Examples for Biomedical NLP Tasks
- Are clinicians ethically obligated to disclose their use of medical machine learning systems to patients?
- Now You See It, Now You Dont: Adversarial Vulnerabilities in Computational Pathology
- Adversarial Robustness through the Lens of Convolutional Filters
- Developing Future Human-Centered Smart Cities: Critical Analysis of Smart City Security, Interpretability, and Ethical Challenges
- AED-PADA:Improving Generalizability of Adversarial Example Detection via Principal Adversarial Domain Adaptation
- Defending against adversarial attacks on medical imaging AI system, classification or detection?
- Local Reweighting for Adversarial Training
- Stress Test Evaluation of Biomedical Word Embeddings
- Revisiting Adversarial Robustness Distillation: Robust Soft Labels Make Student Better
- RobOT: Robustness-Oriented Testing for Deep Learning Systems
- Kryptonite: An Adversarial Attack Using Regional Focus
- Trust and Medical AI: The challenges we face and the expertise needed to overcome them
- No Surprises: Training Robust Lung Nodule Detection for Low-Dose CT Scans by Augmenting with Adversarial Attacks
- Fooling Adversarial Training with Inducing Noise
- Medical Aegis: Robust adversarial protectors for medical images
- Adaptive Input-image Normalization for Solving the Mode Collapse Problem in GAN-based X-ray Images
- Difficulty Translation in Histopathology Images
- Targeted Attack for Deep Hashing based Retrieval
- Adversarial Heart Attack: Neural Networks Fooled to Segment Heart Symbols in Chest X-Ray Images
- A Hierarchical Feature Constraint to Camouflage Medical Adversarial Attacks
- FireBERT: Hardening BERT-based classifiers against adversarial attack
- ProARD: progressive adversarial robustness distillation: provide wide range of robust students
- AdvScan: Black-Box Adversarial Example Detection at Runtime through Power Analysis
- Attack-agnostic Adversarial Detection on Medical Data Using Explainable Machine Learning
- Adversarial Interaction Attack: Fooling AI to Misinterpret Human Intentions
- Dual Head Adversarial Training
- T-MLA: A targeted multiscale log-exponential attack framework for neural image compression