arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 1907.10456cs.CVcs.LGeess.IV

Understanding Adversarial Attacks on Deep Learning Based Medical Image Analysis Systems

  • Beihang University(北京航空航天大学)
  • The University of Melbourne(墨尔本大学)
  • National Institute of Informatics(国立信息学研究所)
  • Shanghai Jiao Tong University(上海交通大学)
  • Chinese Academy of Sciences(中国科学院)

机构由 AI 辅助整理,请以论文原文为准。

Xingjun Ma, Yuhao Niu, Lin Gu, Yisen Wang, Yitian Zhao, James Bailey, Feng Lu

更新

英文摘要:

Deep neural networks (DNNs) have become popular for medical image analysis tasks like cancer diagnosis and lesion detection. However, a recent study demonstrates that medical deep learning systems can be compromised by carefully-engineered adversarial examples/attacks with small imperceptible perturbations. This raises safety concerns about the deployment of these systems in clinical settings. In this paper, we provide a deeper understanding of adversarial examples in the context of medical images. We find that medical DNN models can be more vulnerable to adversarial attacks compared to models for natural images, according to two different viewpoints. Surprisingly, we also find that medical adversarial attacks can be easily detected, i.e., simple detectors can achieve over 98% detection AUC against state-of-the-art attacks, due to fundamental feature differences compared to normal examples. We believe these findings may be a useful basis to approach the design of more explainable and secure medical deep learning systems.

补充信息

↑