Survey on Adversarial Attack and Defense for Medical Image Analysis: Methods and Challenges
arXiv:2303.14133 · doi:10.1145/3702638
Abstract
Deep learning techniques have achieved superior performance in computer-aided medical image analysis, yet they are still vulnerable to imperceptible adversarial attacks, resulting in potential misdiagnosis in clinical practice. Oppositely, recent years have also witnessed remarkable progress in defense against these tailored adversarial examples in deep medical diagnosis systems. In this exposition, we present a comprehensive survey on recent advances in adversarial attacks and defenses for medical image analysis with a systematic taxonomy in terms of the application scenario. We also provide a unified framework for different types of adversarial attack and defense methods in the context of medical image analysis. For a fair comparison, we establish a new benchmark for adversarially robust medical diagnosis models obtained by adversarial training under various scenarios. To the best of our knowledge, this is the first survey paper that provides a thorough evaluation of adversarially robust medical diagnosis models. By analyzing qualitative and quantitative results, we conclude this survey with a detailed discussion of current challenges for adversarial attack and defense in medical image analysis systems to shed light on future research directions. Code is available on \href{https://github.com/tomvii/Adv_MIA}{\color{red}{GitHub}}.
Accepted by ACM Computing Surveys (CSUR) (DOI: https://doi.org/10.1145/3702638)
References in corpus (13)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Towards Evaluating the Robustness of Deep Diagnostic Models by Adversarial Attack
- Volumetric Medical Image Segmentation: A 3D Deep Coarse-to-fine Framework and Its Adversarial Examples
- InfoAT: Improving Adversarial Training Using the Information Bottleneck Principle
- Fuzzy Unique Image Transformation: Defense Against Adversarial Attacks On Deep COVID-19 Models
- Now You See It, Now You Dont: Adversarial Vulnerabilities in Computational Pathology
- Robust CLIP: Unsupervised Adversarial Fine-Tuning of Vision Embeddings for Robust Large Vision-Language Models
- Kryptonite: An Adversarial Attack Using Regional Focus
- Adaptive Adversarial Training to Improve Adversarial Robustness of DNNs for Medical Image Segmentation and Detection
- A Kernelized Manifold Mapping to Diminish the Effect of Adversarial Perturbations
- Adversarial Heart Attack: Neural Networks Fooled to Segment Heart Symbols in Chest X-Ray Images
- RoS-KD: A Robust Stochastic Knowledge Distillation Approach for Noisy Medical Imaging
- Dynamic Perturbation-Adaptive Adversarial Training on Medical Image Classification