Evaluating and enhancing the robustness of vision transformers against adversarial attacks in medical imaging

被引:1
作者
Kanca, Elif [1 ]
Ayas, Selen [2 ]
Kablan, Elif Baykal [1 ]
Ekinci, Murat [2 ]
机构
[1] Karadeniz Tech Univ, Dept Software Engn, Trabzon, Turkiye
[2] Karadeniz Tech Univ, Dept Comp Engn, Trabzon, Turkiye
关键词
Adversarial attacks; Adversarial defense; Vision transformer; Medical image classification; DIABETIC-RETINOPATHY; VALIDATION;
D O I
10.1007/s11517-024-03226-5
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Deep neural networks (DNNs) have demonstrated exceptional performance in medical image analysis. However, recent studies have uncovered significant vulnerabilities in DNN models, particularly their susceptibility to adversarial attacks that manipulate these models into making inaccurate predictions. Vision Transformers (ViTs), despite their advanced capabilities in medical imaging tasks, have not been thoroughly evaluated for their robustness against such attacks in this domain. This study addresses this research gap by conducting an extensive analysis of various adversarial attacks on ViTs specifically within medical imaging contexts. We explore adversarial training as a potential defense mechanism and assess the resilience of ViT models against state-of-the-art adversarial attacks and defense strategies using publicly available benchmark medical image datasets. Our findings reveal that ViTs are vulnerable to adversarial attacks even with minimal perturbations, although adversarial training significantly enhances their robustness, achieving over 80% classification accuracy. Additionally, we perform a comparative analysis with state-of-the-art convolutional neural network models, highlighting the unique strengths and weaknesses of ViTs in handling adversarial threats. This research advances the understanding of ViTs robustness in medical imaging and provides insights into their practical deployment in real-world scenarios.Graphical Abstract(left).
引用
收藏
页码:673 / 690
页数:18
相关论文
共 54 条
[1]   Advances in Adversarial Attacks and Defenses in Computer Vision: A Survey [J].
Akhtar, Naveed ;
Mian, Ajmal ;
Kardan, Navid ;
Shah, Mubarak .
IEEE ACCESS, 2021, 9 :155161-155196
[2]  
Aldahdooh A., 2021, arXiv
[3]  
Ali K, 2024, IEEE Access
[4]   Self-Ensembling Vision Transformer (SEViT) for Robust Medical Image Classification [J].
Almalik, Faris ;
Yaqub, Mohammad ;
Nandakumar, Karthik .
MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION, MICCAI 2022, PT III, 2022, 13433 :376-386
[5]   Review of deep learning: concepts, CNN architectures, challenges, applications, future directions [J].
Alzubaidi, Laith ;
Zhang, Jinglan ;
Humaidi, Amjad J. ;
Al-Dujaili, Ayad ;
Duan, Ye ;
Al-Shamma, Omran ;
Santamaria, J. ;
Fadhel, Mohammed A. ;
Al-Amidie, Muthana ;
Farhan, Laith .
JOURNAL OF BIG DATA, 2021, 8 (01)
[6]  
[Anonymous], 2021, FDA permits marketing of e-cigarette products, making first authorization of its kind by the agency
[7]  
[Anonymous], 2018, Diabetic retinopathy detection
[8]  
[Anonymous], 2011, IEEE 105-108
[9]   BACH: Grand challenge on breast cancer histology images [J].
Aresta, Guilherme ;
Araujo, Teresa ;
Kwok, Scotty ;
Chennamsetty, Sai Saketh ;
Safwan, Mohammed ;
Alex, Varghese ;
Marami, Bahram ;
Prastawa, Marcel ;
Chan, Monica ;
Donovan, Michael ;
Fernandez, Gerardo ;
Zeineh, Jack ;
Kohl, Matthias ;
Walz, Christoph ;
Ludwig, Florian ;
Braunewell, Stefan ;
Baust, Maximilian ;
Quoc Dang Vu ;
Minh Nguyen Nhat To ;
Kim, Eal ;
Kwak, Jin Tae ;
Galal, Sameh ;
Sanchez-Freire, Veronica ;
Brancati, Nadia ;
Frucci, Maria ;
Riccio, Daniel ;
Wang, Yaqi ;
Sun, Lingling ;
Ma, Kaiqiang ;
Fang, Jiannan ;
Kone, Ismael ;
Boulmane, Lahsen ;
Campilho, Aurelio ;
Eloy, Catarina ;
Polonia, Antonio ;
Aguiar, Paulo .
MEDICAL IMAGE ANALYSIS, 2019, 56 :122-139
[10]   Projected Gradient Descent Adversarial Attack and Its Defense on a Fault Diagnosis System [J].
Ayas, Mustafa Sinasi ;
Ayas, Selen ;
Djouadi, Seddik M. .
2022 45TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING, TSP, 2022, :36-39