Benchmarking the Robustness of Segmentation Methods Against Adversarial Attacks in Breast Ultrasound Segmentation
摘要
This study presents a comprehensive robustness analysis of five segmentation models—UResNet, DeepLabV3, TransUnet, SAM, and Efficient SAM (ESAM)—for breast ultrasound (BUS) image segmentation under adversarial attacks. Each model is initially trained on a clean BUS dataset, followed by systematic evaluation against five widely-used adversarial techniques: FGSM, BIM, PGD, PGDL2, and Jitter. Model performance is quantitatively evaluated using tumor IoU, background IoU, and mean IoU metrics on both clean and adversarial data. Experimental results show that CNN-based models, such as UResNet and DeepLabV3, were more resilient to adversarial perturbations, maintaining higher accuracy compared to transformer-based models like TransUnet, SAM, and the lightweight ESAM, which exhibited significant vulnerability. These findings emphasize the importance of robustness evaluations in medical imaging and other high-stakes applications, where performance degradation can result in serious consequences. This study highlights the need for developing more robust models and effective defense strategies to enhance the reliability of medical image segmentation systems in clinical applications.