Nowhere to Hide: Toward Robust Reactive Medical Adversarial Defense

Qingsong Yao,Zecheng He,Xiaodong Yu,S. Kevin Zhou
DOI: https://doi.org/10.1109/isbi56570.2024.10635644
2024-01-01
Abstract:Medical image systems based on deep neural networks are highly vulnerable to adversarial examples. Despite numerous defense mechanisms, these approaches typically assume a passive attacker with limited knowledge of the defense system and a lack of adaptability in attack strategies based on defense details. Recent works [1], [2], [3], [4] expose the vulnerability of existing defenses against adaptive attacks, where the attacker, leveraging comprehensive knowledge of the defense, can pose a substantial threat. In this paper, we make the novel observation that shallow features exhibit a higher degree of robustness compared to deep features. Based on this insight, we propose a novel adversarial defense called Medical Adversarial Shield (MAS), which is adversarially trained to capture the unique characteristics left by the attackers in feature space, particularly within shallow features. Extensive experimental results confirm the effectiveness of our MAS as the first defense capable of accurately distinguishing both strong adaptive attacks and conventional attacks, showing significant improvements compared to existing reactive defenses.
What problem does this paper attempt to address?