错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Making Domain Specific Adversarial Attacks for Retinal Fundus Images

  • Nirmal Joseph,
  • P. M. Ameer,
  • Sudhish N. George,
  • Kiran Raja

摘要

Adversarial attacks on deep neural networks (DNN) aim at creating perturbations that can lead to misclassification by intention, despite being imperceptible. This work presents a new approach for creating adversarial samples for retinal fundus images by not only introducing imperceptible noise, but make them visually realistic by introducing domain specific details. Specifically, we introduce exudates on to retinal fundus images to make a healthy image appear as a diabetic image. With such an approach, the work is intended to make both DNN based systems and human observers such as medical practitioners to misclassify a healthy image as a diabetic image. The generated images through new attack are further validated using a DNN based classifier and human observers (3 practitioners and 30 normal observers) to demonstrate the strength of the attacks. While the generated images are misclassified with 100% success in a DNN classifier, we also show that the images can realistically fool humans when domain specific details are added through a set of experiments conducted on a publicly available dataset. The evaluation indicates high degree of attacks for instance in insurance frauds, and demonstrates the need for better attack detection methods.