Adversarial attacks pose significant threats to deep learning (DL) models by introducing subtle perturbations that impair performance. Medical DL models are particularly vulnerable to these attacks, which can occur during training (causative attacks) or inference (exploratory attacks), compromising model accuracy or misclassifying specific predictions. This research paper presents a framework to expose the vulnerability of medical DL models, using ISIC-2019 dermoscopic image datasets. The Warping Based Backdoor Attack and the Universal Adversarial Pattern Attack were examined for their effectiveness in creating undetectable adversarial samples. Experiments on models with over 80% accuracy reveal that both attack types can reduce accuracy by at least 70%, with the most effective attacks reducing accuracy by up to 90%. These results highlight the critical need for robust medical DL models resistant to adversarial attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adversarial Attacks in Medical Deep Learning System

  • Young Kang Lau,
  • Brian Chung Shiong Loh,
  • Wan Tze Vong,
  • Patrick Hang Hui Then

摘要

Adversarial attacks pose significant threats to deep learning (DL) models by introducing subtle perturbations that impair performance. Medical DL models are particularly vulnerable to these attacks, which can occur during training (causative attacks) or inference (exploratory attacks), compromising model accuracy or misclassifying specific predictions. This research paper presents a framework to expose the vulnerability of medical DL models, using ISIC-2019 dermoscopic image datasets. The Warping Based Backdoor Attack and the Universal Adversarial Pattern Attack were examined for their effectiveness in creating undetectable adversarial samples. Experiments on models with over 80% accuracy reveal that both attack types can reduce accuracy by at least 70%, with the most effective attacks reducing accuracy by up to 90%. These results highlight the critical need for robust medical DL models resistant to adversarial attacks.