How effective is adversarial training of CNNs in medical image analysis?
File(s) XieEtFetit_MIUA_2022.pdf (475.79 KB)
Accepted version
Author(s)
Xie, Yiming
Fetit, Ahmed
Type
Conference Paper
Abstract
Adversarial attacks are carefully crafted inputs that can deceive machine learning models into giving wrong results with seemingly
high confidence. One approach that is commonly used in the image analysis literature to defend against such attacks is the introduction of adversarial images during training time, i.e. adversarial training. However,
the effectiveness of adversarial training remains unclear in the healthcare domain, where the use of complex medical scans is crucial for a
wide range of clinical workflows. In this paper, we carried out an empirical investigation into the effectiveness of adversarial training as a defence
technique in the context of medical images. We demonstrated that adversarial training is, in principle, a transferable defence on medical imaging
data, and that it can potentially be used on attacks previously unseen by
the model. We also empirically showed that the strength of the attack,
determined by the parameter ϵ, and the percentage of adversarial images
included during training, have key influence over the level of success of
the defence. Our analysis was carried out using 58,954 images from the
publicly available MedNIST benchmarking dataset.
high confidence. One approach that is commonly used in the image analysis literature to defend against such attacks is the introduction of adversarial images during training time, i.e. adversarial training. However,
the effectiveness of adversarial training remains unclear in the healthcare domain, where the use of complex medical scans is crucial for a
wide range of clinical workflows. In this paper, we carried out an empirical investigation into the effectiveness of adversarial training as a defence
technique in the context of medical images. We demonstrated that adversarial training is, in principle, a transferable defence on medical imaging
data, and that it can potentially be used on attacks previously unseen by
the model. We also empirically showed that the strength of the attack,
determined by the parameter ϵ, and the percentage of adversarial images
included during training, have key influence over the level of success of
the defence. Our analysis was carried out using 58,954 images from the
publicly available MedNIST benchmarking dataset.
Date Issued
2022-07-25
Date Acceptance
2022-05-31
Citation
Lecture Notes in Computer Science, 2022, pp.443-457
ISSN
0302-9743
Publisher
Springer
Start Page
443
End Page
457
Journal / Book Title
Lecture Notes in Computer Science
Copyright Statement
© 2022 The Author(s), under exclusive license to Springer Nature Switzerland AG. This version of the article has been accepted for publication, after peer review (when applicable) and is subject to Springer Nature’s AM terms of use, but is not the Version of Record and does not reflect post-acceptance improvements, or any corrections. The Version of Record is available online at: https://doi.org/10.1007/978-3-031-12053-4_33
Identifier
https://link.springer.com/chapter/10.1007/978-3-031-12053-4_33
Source
26th UK Conference on Medical Image Understanding and Analysis
Publication Status
Published
Start Date
2022-07-27
Finish Date
2022-07-29
Coverage Spatial
Cambridge, United Kingdom
Date Publish Online
2022-07-25
