<p>Convolutional Neural Networks (CNNs) have markedly enhanced the accuracy of medical diagnostics, particularly in detecting lung diseases. The widespread adoption of pre-trained models such as ResNet50 and EfficientNetB0 in medical image analysis is driven by the limited availability of annotated datasets and substantial computational requirements. Despite their advantages, these models remain susceptible to adversarial attacks, potentially compromising diagnostic precision. Current research predominantly assesses the robustness of these models against various challenges such as noise, data diversity, distribution shifts, shortcut learning, and out-of-distribution scenarios, leaving a gap in evaluations specifically against adversarial attacks. This study addresses this critical gap by evaluating the resilience of pre-trained models against adversarial examples within medical settings, utilizing advanced techniques including the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). Our results demonstrate that ResNet50, with its intricate architecture featuring residual connections, exhibits significantly greater resilience to adversarial attacks compared to EfficientB0 and Customized CNN, notably in pneumonia detection. This architectural sophistication not only stabilizes training and enhances gradient flow but also manages the curse of dimensionality effectively. As a result, ResNet50 consistently identifies crucial diagnostic features even under increased perturbations, underscoring the importance of architectural complexity and model linearity in mitigating adversarial risks. This study contributes to a deeper understanding of security in medical diagnostic models and proposes a novel robustness metric. This metric, designed to incorporate unique adversarial attributes, aims to standardize the evaluation of deep learning models in healthcare, thereby boosting the reliability of these critical technologies in diagnostic applications.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adversarial attacks and adversarial robustness in pre-trained deep learning models for disease diagnosis

  • Dua’a M. Akhtom,
  • Manmeet Mahinderjit Singh,
  • Chew XinYing

摘要

Convolutional Neural Networks (CNNs) have markedly enhanced the accuracy of medical diagnostics, particularly in detecting lung diseases. The widespread adoption of pre-trained models such as ResNet50 and EfficientNetB0 in medical image analysis is driven by the limited availability of annotated datasets and substantial computational requirements. Despite their advantages, these models remain susceptible to adversarial attacks, potentially compromising diagnostic precision. Current research predominantly assesses the robustness of these models against various challenges such as noise, data diversity, distribution shifts, shortcut learning, and out-of-distribution scenarios, leaving a gap in evaluations specifically against adversarial attacks. This study addresses this critical gap by evaluating the resilience of pre-trained models against adversarial examples within medical settings, utilizing advanced techniques including the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). Our results demonstrate that ResNet50, with its intricate architecture featuring residual connections, exhibits significantly greater resilience to adversarial attacks compared to EfficientB0 and Customized CNN, notably in pneumonia detection. This architectural sophistication not only stabilizes training and enhances gradient flow but also manages the curse of dimensionality effectively. As a result, ResNet50 consistently identifies crucial diagnostic features even under increased perturbations, underscoring the importance of architectural complexity and model linearity in mitigating adversarial risks. This study contributes to a deeper understanding of security in medical diagnostic models and proposes a novel robustness metric. This metric, designed to incorporate unique adversarial attributes, aims to standardize the evaluation of deep learning models in healthcare, thereby boosting the reliability of these critical technologies in diagnostic applications.