CalCErt:医学图像分类中置信度校准的逐桶认证
CalCErt: Bin-wise Certification of Confidence Calibration in Medical Image Classification
浏览论文内容
中文总结 AI 辅助
CalCErt提出一种事后认证方法,通过结合经验校准、统计界限和Lipschitz估计,在对抗扰动下为医学图像分类提供逐桶置信度校准保证,并在11个任务中验证了高覆盖率与紧致性。
中文摘要 AI 辅助
深度神经网络仍然容易受到对抗性扰动的影响,这些扰动不仅会扭曲预测结果,还会扭曲置信度分数,从而破坏不确定性校准。虽然现有的认证方法侧重于保持预测类别,但在对抗性攻击下校准行为的保证仍然被忽视。在这项工作中,我们引入了CalCErt,一种简单且高效的事后策略,用于对任何预训练的可微分类器进行逐桶置信度校准认证。我们的方法结合了经验校准估计、统计集中界限和置信度函数的局部Lipschitz估计,以推导在半径为R的$\ell_2$-球内最坏情况误校准的数据相关上界。我们在11个医学图像分类任务和多种对抗性扰动下评估了CalCErt,证明了其认证覆盖率显著高于基线策略,同时保持了具有竞争力的紧致性。我们的代码可在该URL获取。
英文摘要
Deep neural networks remain vulnerable to adversarial perturbations, which can distort not only predictions but also confidence scores, undermining uncertainty calibration. While existing certification methods focus on preserving the predicted category, providing guarantees on how calibration behaves under adversarial attacks remains overlooked. In this work, we introduce CalCErt, a simple and efficient post-hoc strategy that certifies bin-wise confidence calibration for any pretrained differentiable classifier. Our approach combines empirical calibration estimates, statistical concentration bounds, and local Lipschitz estimates of the confidence function to derive data-dependent upper bounds on worst-case miscalibration within an $ell_2$-ball of radius R. We evaluate CalCErt across 11 medical image classification tasks and multiple adversarial perturbations, demonstrating substantially higher certified coverage than baseline strategies while maintaining competitive tightness. Our code is available at https://github.com/leofillioux/calcert.
发表机构
- Université Paris-Saclay, CentraleSupélec, Gustave Roussy, INSERM, CDSU, IHU PRISM, Gif-sur-Yvette(巴黎-萨克雷大学,中央高等电力学院,古斯塔夫·鲁西研究所,法国国家健康与医学研究院,CDSU,IHU PRISM,吉夫-苏尔-伊韦特)
- LIVIA, ILLS, ETS Montréal(LIVIA,ILLS,蒙特利尔高等工程技术学院)
机构由 AI 辅助整理,请以论文原文为准。