Graph-Regularized Adversarial Training in Breast Ultrasound Classification
摘要
Deep neural networks for breast ultrasound classification remain highly vulnerable to adversarial perturbations, raising concerns about clinical reliability. Building on the Graph Regularized Adversarial Training (GReAT) framework, we investigate its effectiveness on breast ultrasound imaging. In addition to PGD-based GReAT, we extend the framework with a TRADES-based variant to explore the trade-off between robustness and clean accuracy. The graph term exploits intrinsic sample relationships, while the adversarial component strengthens resilience against perturbations. Experiments on BUSI, BUS-UCLM, and their combined dataset demonstrate that GReAT substantially improves resistance to FGSM, PGD, and AutoAttack while maintaining competitive clean accuracy. Quantitative improvements are consistent across datasets, with GReAT variants achieving up to 20% higher adversarial accuracy than standard adversarial training. Graph-based visualizations corroborate these gains by illustrating preserved neighborhood structures in the embedding space. These results highlight the potential of GReAT for developing robust and reliable computer-aided diagnosis systems.