Robust Convolutional Neural Networks Against Adversarial Attacks on Medical Images

Xiaoshuang Shi,Yifan Peng,Qingyu Chen,Tiarnan Keenan,Alisa T. Thavikulwat,Sungwon Lee,Yuxing Tang,Emily Y. Chew,Ronald M. Summers,Zhiyong Lu
DOI: https://doi.org/10.1016/j.patcog.2022.108923
IF: 8
2022-01-01
Pattern Recognition
Abstract:Convolutional neural networks (CNNs) have been widely applied to medical images. However, medical images are vulnerable to adversarial attacks by perturbations that are undetectable to human experts. This poses significant security risks and challenges to CNN-based applications in clinic practice. In this work, we quantify the scale of adversarial perturbation imperceptible to clinical practitioners and in-vestigate the cause of the vulnerability in CNNs. Specifically, we discover that noise (i.e., irrelevant or corrupted discriminative information) in medical images might be a key contributor to performance de-terioration of CNNs against adversarial perturbations, as noisy features are learned unconsciously by CNNs in feature representations and magnified by adversarial perturbations. In response, we propose a novel defense method by embedding sparsity denoising operators in CNNs for improved robustness. Tested with various state-of-the-art attacking methods on two distinct medical image modalities, we demon-strate that the proposed method can successfully defend against those unnoticeable adversarial attacks by retaining as much as over 90% of its original performance. We believe our findings are critical for improving and deploying CNN-based medical applications in real-world scenarios. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
What problem does this paper attempt to address?