Adversarial Exposure Attack on Diabetic Retinopathy Imagery Grading
arXiv:2009.09231 · doi:10.1109/JBHI.2024.3469630
Abstract
Diabetic Retinopathy (DR) is a leading cause of vision loss around the world. To help diagnose it, numerous cutting-edge works have built powerful deep neural networks (DNNs) to automatically grade DR via retinal fundus images (RFIs). However, RFIs are commonly affected by camera exposure issues that may lead to incorrect grades. The mis-graded results can potentially pose high risks to an aggravation of the condition. In this paper, we study this problem from the viewpoint of adversarial attacks. We identify and introduce a novel solution to an entirely new task, termed as adversarial exposure attack, which is able to produce natural exposure images and mislead the state-of-the-art DNNs. We validate our proposed method on a real-world public DR dataset with three DNNs, e.g., ResNet50, MobileNet, and EfficientNet, demonstrating that our method achieves high image quality and success rate in transferring the attacks. Our method reveals the potential threats to DNN-based automatic DR grading and would benefit the development of exposure-robust DR grading methods in the future.
13 pages, 7 figures
References in corpus (14)
- Explaining and Harnessing Adversarial Examples
- Intriguing properties of neural networks
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- One pixel attack for fooling deep neural networks
- Grader variability and the importance of reference standards for evaluating machine learning models for diabetic retinopathy
- Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods
- Evaluation of Retinal Image Quality Assessment Networks in Different Color-spaces
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial Attacks
- Watch out! Motion is Blurring the Vision of Your Deep Neural Networks
- Walking on the Edge: Fast, Low-Distortion Adversarial Examples
- Pixle: a fast and effective black-box attack based on rearranging pixels
- Unified Adversarial Patch for Cross-modal Attacks in the Physical World
- RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical World
- Breaking Temporal Consistency: Generating Video Universal Adversarial Perturbations Using Image Models